Back to skill

Security audit

客服会话质检

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent customer-service conversation quality-check helper that handles sensitive chat exports locally with disclosed masking and review safeguards.

Installers should treat customer-service chat exports as sensitive: use this skill when you intentionally want QC/scoring, confirm ambiguous requests before processing large private exports, and manually review the generated report before using it for employee evaluation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "帮我质检这批客服会话" and the description that even tasks not explicitly mentioning "质检" still fall within this skill's scope make activation criteria broad. This can cause the skill to intercept generic requests about reviewing customer-service chats, leading to unintended access to sensitive conversation exports and misrouting away from more appropriate skills or general handling.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description broadens activation to any user request involving customer-service conversation evaluation, even when the user did not explicitly ask for quality-control processing. This can cause inappropriate auto-invocation, leading to unintended handling of sensitive chat logs and misapplication of a scoring workflow outside the user's intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.