Back to skill

Security audit

It Consulting Workbench 1.1.0

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only IT consulting playbook with some broad and privacy-sensitive guidance, but no hidden execution, exfiltration, persistence, or deceptive install behavior.

Install only if you want a broad Chinese-language IT consulting workbench. Before following its checklists, confirm client authorization, avoid unnecessary personal profiling, minimize access to logs/code/production data, adapt jurisdiction-specific advice, and require approval plus rollback plans for any cloud shutdown or resource reclamation automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README advertises very broad natural-language triggers such as generic consulting requests, which can cause the skill to activate in situations the user did not explicitly intend. In an agent environment, overbroad invocation increases the chance of context hijacking, accidental execution of the wrong workflow, or unintended capture of sensitive business discussions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill defines a large quick-routing table with natural-language examples such as '我们约个会聊聊' and '介绍一下你们能做什么', which are common conversational phrases rather than narrowly scoped commands. This can cause accidental invocation or over-application of the skill in unrelated contexts, leading the agent to steer conversations into a complex consulting workflow without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description promotes 90+ Chinese and English aliases with no visible constraints on when the skill should activate. An excessively broad trigger surface increases the chance that unrelated enterprise, project, or even casual discussions will be captured by this skill, creating scope confusion and unintended instruction takeover.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The metadata hard-codes 'language: zh-CN', which can override user preference or locale expectations when the skill is invoked. While not directly a code-execution risk, forced locale behavior can degrade usability, cause miscommunication, and in security- or compliance-related consulting scenarios lead to incorrect interpretation of requirements or outputs.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The file explicitly instructs activation based on very broad, vague customer problem statements such as '系统很慢' or 'IT成本太高'. Without tighter scope checks, confirmation steps, or exclusion conditions, the skill may trigger in conversations where the user is only mentioning symptoms casually, causing unintended routing into this skill and potentially steering advice before the real task is understood.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The decision tree uses common conversational complaints as top-level entry points across a large span of scenarios, but it does not define boundaries for when the skill should not engage. In a broad workbench skill with many trigger aliases, this increases the chance of over-activation, accidental interception of unrelated conversations, and premature diagnostic framing that may bias the assistant's behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The guidance explicitly tells users to research and record stakeholders' social-profile activity, career history, and interpersonal relationships, including who they conflict with, without any privacy, consent, minimization, or lawful-use guardrails. In an enterprise consulting context, this can normalize collection of sensitive personal or reputational data and create misuse risks such as covert profiling, workplace surveillance, or inappropriate retention of non-essential personal information.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The workflow hard-codes China-specific policy analysis ('数字中国', 信创, 国资委考核, 数据出境合规) as the mandatory starting point for IT strategy design, without asking whether the client operates in China or under PRC jurisdiction. In a consulting skill, this can systematically bias recommendations, create compliance or procurement misdirection for non-China clients, and pressure users into jurisdictionally inappropriate strategic assumptions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The playbook explicitly requests access to code repositories, systems, monitoring, and logs, but provides no guidance on handling confidential, personal, or production data during due diligence. In a consulting skill focused on technical assessment, this omission increases the chance of over-collection, inappropriate access, or insecure handling of sensitive information by users following the checklist.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The instruction to assess employee job-change frequency using external LinkedIn data encourages collection and use of personal profile information without any privacy, consent, or accuracy guidance. While less severe than direct system-access issues, it can lead to unnecessary personal-data processing, profiling concerns, and unreliable conclusions in a due-diligence context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file recommends automated actions such as budget-triggered shutdowns, idle-resource reclamation, and automatic remediation without clearly requiring approval gates, environment scoping, rollback plans, or explicit service-impact warnings. In an IT consulting/FinOps workbench, operators may treat this as prescriptive guidance and apply it to production-adjacent systems, causing outages, data loss, or disruption of critical business services.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.