Back to skill

Security audit

Qqlive

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable Tencent Video guidance skill with some broad media-advice content, but no hidden install behavior, credential handling, persistence, or harmful actions.

Installers should understand that this skill may answer broader Tencent Video entertainment and creator questions, not only membership or device-limit questions. Verify current membership prices and platform rules on Tencent Video directly before buying, and do not rely on it for account-specific, legal, or financial decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest advertises a narrowly scoped Tencent Video membership and device-limit troubleshooting guide, but the body expands into general entertainment recommendation, plot analysis, reviews, and creator monetization advice. This scope drift can cause the orchestrator or user to trust and invoke the skill for a constrained purpose while the skill steers interactions into broader, less-reviewed behaviors, increasing the chance of policy bypass, poor routing, or unvetted advice.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The in-file introduction presents the assistant as a broad Tencent Video content and creator advisor, contradicting the manifest's much narrower usage-guide purpose. Such contradictions weaken trust assumptions and can let a skill operate outside the reviewed contract, which is dangerous in agent systems that rely on metadata for capability scoping and safety decisions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.