Back to skill

Security audit

benzhi

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only analysis framework with no code execution, credentials, external access, or install-time behavior; its main caveats are broad trigger wording and optional-looking self-learning notes.

Safe to install as a reasoning aid. Expect it to steer some broad why-questions into a structured deep-analysis format; disable or narrow it if that feels intrusive. If your agent has long-term memory enabled, require confirmation before saving analysis logs or derived insights.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description explicitly activates on generic "为什么XX" questions, which is far broader than the stated purpose of analyzing the essence of a topic. This can cause the skill to intercept ordinary explanatory queries and apply an opinionated reasoning framework where users likely expected normal assistance, creating prompt-collision and unintended tool invocation risk.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger section includes ambiguous catch-all language like "任何明确要求分析本质的问题" alongside generic "为什么XX?", making activation boundaries unclear. In agent environments, ambiguous routing increases accidental invocation, can override more appropriate skills, and may steer benign conversations into unnecessary deep analysis workflows.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The core principle states that either "本质" or "为什么" can trigger the skill, formalizing an overly broad activation rule at the policy level. Because this appears in the governing principles, it is more dangerous than an isolated example: it encourages systematic over-triggering and increases the chance of collisions with normal conversation or other skills.

Ssd 3

Medium
Confidence
92% confidence
Finding
The passive logging section instructs the skill to record context, conclusions, core variables, meta-insights, counter-examples, and confidence after each analysis. Even though it is framed as self-learning, this creates a natural-language retention pattern for potentially sensitive user inputs and derived inferences, which can expose private information or persist sensitive analytical content beyond the immediate session.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.