Miantiao Career Advisor

Security checks across malware telemetry and agentic risk

Overview

This appears to be a workplace or career-advice persona skill with broad triggers, but no evidence of hidden access, credential use, persistence, or destructive behavior.

Install this if you want a workplace/career-advice persona that may respond whenever common job-related topics come up. If you only want it for explicit career-coaching requests, narrow the trigger terms or disable it for general chat contexts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is extremely broad and contains common workplace terms such as '老板', '同事', '工资', and '面试', which can cause the skill to activate for many ordinary conversations that only loosely relate to the intended persona. Over-triggering is dangerous because it can route users into a constrained persona with strict response rules, increasing the chance of irrelevant advice, user confusion, or bypass of better-suited skills.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal