Back to skill

Security audit

smart-construction-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese smart-construction reporting skill, with the main caution that its bundled Word script is a fixed report generator rather than live analysis by itself.

Install only if you want a Chinese-language smart-construction research workflow and are comfortable enabling PatSnap MCP and web research tools. Before relying on output, verify that live searches were actually run and that the generated HTML or Word report cites current sources, because the included Word generator alone writes a fixed report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
描述把该技能定位为一个会基于多来源数据自动开展深度技术分析并输出 HTML/Word 双格式报告的分析系统,但实际代码只有一个 python-docx 脚本,用于写出固定章节、固定表格、固定案例内容的 Word 文档。代码没有网络访问、数据库访问、检索专利/文献/报道、动态分析、主体识别或竞争评估逻辑,主入口脚本也仅打印“Skill script ready”。因此其主要功能与声明存在明显实质性不符。

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description is entirely written in Chinese and presents the skill as producing its analysis/reporting behavior in that language, with no indication that users may choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This markdown file contains natural-language guidance only in Chinese, and nowhere indicates that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This code file contains natural-language strings that force a specific language/locale for usage instructions and generated report content. Under the policy, language constraints should offer user choice or be explicitly justified as region-specific; neither is present here.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.