伐谋 - 任务定义与评估器生成

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed FaMou task-generation helper that reads local project context, writes named task files, and validates them without hidden install hooks or credential behavior.

Install this if you want an agent to help create FaMou task materials. Use it in a clean or version-controlled workspace because it may inspect local project files, overwrite the named task files, and run generated Python during validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger criteria are intentionally very broad and explicitly include vague requests or rough ideas, which increases the chance this skill activates when the user did not clearly ask for FaMou task generation. Over-broad activation can cause context hijacking, inappropriate workflow takeover, and unintended access or analysis of project files and data that are unrelated to the user's actual intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal