Back to skill

Security audit

产品定位大师

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a business-analysis helper with a broad trigger list, but the supplied evidence does not show hidden behavior, destructive actions, persistence, or credential misuse.

Install is reasonable if you want a business or market-analysis assistant. Watch for accidental activation on generic terms like SWOT, STP, 4P, 市场分析, or 竞品分析, and confirm the intended workflow before sharing sensitive business details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list is broad enough that ordinary business conversations mentioning generic terms like SWOT, STP, 4P, 市场分析, or 竞品分析 could activate the skill unintentionally. In an agent environment, unintended activation can cause prompt-routing errors, inappropriate disclosure of user context to the skill, or execution of the wrong workflow, even though the README itself contains no overtly malicious behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.