Back to skill

Security audit

找客户 · Find Customers|销售线索与评论区获客

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed social-media lead-finding workflow that uses public comments and optional user-authorized platform/login flows, with privacy and invocation-scope caveats users should understand.

Install only if you intentionally want a sales-lead workflow that scans public social-media comments, may ask you to log in to Douyin/Xiaohongshu/Kuaishou, and may produce identifiable lead lists. Use it only where platform terms, privacy rules, and outreach laws allow this kind of collection and follow-up, and avoid saving or sharing more personal data than needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger examples include very broad phrases such as '帮我找客户' that can overlap with ordinary conversation and cause the skill to activate in contexts the user did not clearly intend. In a lead-generation skill that processes external platform data and may initiate scraping or analysis flows, accidental invocation increases the risk of unintended data processing and confusing or privacy-impacting actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is broad and action-oriented, telling the agent to immediately search public comments for 'people who want to buy' and produce leads, scripts, and next-step searches without stating user confirmation gates, scope limits, or compliance checks. In a skill that targets customer acquisition from social-media comments, this increases the chance of implicit activation, over-collection, or privacy/targeting misuse when the user request is only loosely related.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The example explicitly instructs the skill to compile potential customer lists using identifiable usernames and verbatim public comments, but it provides no privacy notice, minimization guidance, or restrictions on how that personal data should be collected and shared. Even when comments are public, aggregating identities, inferred purchase intent, and outreach suggestions creates a more sensitive lead dossier that can enable unsolicited profiling or targeting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.