Back to skill

Security audit

DBS 丹纳赫业务系统

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language DBS business reference skill with broad activation terms but no code, credential use, network access, or persistence.

Install this if you want a Chinese-language DBS/Danaher business-method reference. Be aware it may activate on general lean, problem-solving, or M&A prompts, and independently verify business figures before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is extremely broad and includes many common business and management terms such as M&A, problem solving, continuous improvement, and customer voice. This increases the chance of unintended skill activation during unrelated enterprise conversations, which can hijack routing, suppress more appropriate skills, or cause the agent to inject domain-specific guidance when the user did not ask for it.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill metadata and description are written entirely in Chinese without offering a language fallback or documenting a locale restriction. In a multilingual agent environment, this can cause misrouting, user confusion, or opaque behavior if the skill is invoked for users who operate in other languages, reducing transparency and potentially leading to misunderstood advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.