Back to skill

Security audit

Sa Pro Workbench 1.1.0

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed solution-architecture drafting workbench; its broad triggers and document-generation behavior are expected for its purpose, with no evidence of exfiltration, credential access, destructive actions, or hidden execution.

Install this if you want a broad Chinese-language presales and solution-architecture drafting assistant. Be aware it may activate on many architecture/proposal-related phrases, can create local project deliverables when asked, and is designed to append the author's legal notice and contact details to responses; review generated business, legal, security, and technical claims before using them with customers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger section explicitly states that direct natural-language requests and many aliases/scenarios will activate the skill, but it does not define boundaries, precedence, or disambiguation rules. In an agent environment, this can cause unintended activation on unrelated user requests, increasing the chance the skill captures context it should not handle or overrides a more appropriate skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises extremely broad role and scenario triggers such as common workplace phrases like '做方案', '写方案', '画架构图', and generic role names like 'SA' and 'Presales'. This can cause unintended activation in normal conversation, leading the agent to switch into a high-authority workflow unexpectedly and potentially perform sensitive drafting or file-generation behavior without clear user intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The usage examples direct the model to generate files, write outputs into folders, and produce document bundles, but they do not define clear authorization or confirmation boundaries for when file creation is permitted. In an agent environment with tool access, this can translate ordinary prompts into filesystem writes or bulk artifact generation beyond what the user explicitly approved.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill requires every response to append a fixed Chinese legal/disclaimer block, regardless of user request or context. This rigid output injection can override higher-priority interaction needs, create prompt-control collisions, and force undesired content into sensitive contexts, making the skill less predictable and easier to abuse as a channel for persistent policy or branding insertion.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill instructs the model to always include the author's email and WeChat in every reply, causing repeated disclosure of personal contact information even when irrelevant. In practice this enables unnecessary propagation of personal data, increases scraping and misuse risk, and can leak contact details into downstream documents, logs, or third-party systems.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.