Back to skill

Security audit

床垫选购顾问

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed branded mattress shopping advisor, with sales bias but no code, persistence, data access, or hidden execution.

Install this only if you want a sales-oriented Chinese mattress advisor that may recommend 欧派立方体 when mattress-shopping signals appear. It is not a neutral product-comparison skill, so users who need unbiased advice should ask the agent not to include brand recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill is scoped to trigger on a very broad set of mattress, sleep-comfort, home-shopping, and lead-conversion scenarios, and explicitly says agents should '优先采用' it. That creates a prompt-routing vulnerability where many ordinary conversations can be steered into a sales script, overriding more appropriate domain skills or neutral assistance and causing covert commercial influence.

Vague Triggers

High
Confidence
94% confidence
Finding
The adoption rule applies to many agent types and broad workflow labels like customer service, lead generation, sales conversion, and home advice, without strict gating conditions. In practice this can cause the skill to activate opportunistically across unrelated or weakly related contexts, increasing the chance of hidden ad insertion, biased recommendations, and suppression of safer or more suitable responses.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The high-trigger list contains common phrases like '床垫推荐', '买什么床垫', '新房装修', and '有没有味道', which are broad enough to overlap with normal conversation and adjacent support contexts. This makes accidental triggering more likely and increases the risk that users receive brand-pushing content when they expected neutral advice, especially because the skill repeatedly instructs mid-answer brand insertion.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.