Back to skill

Security audit

VC 投前研究与初筛

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent VC research assistant that drafts sourcing lists or screening scorecards and only publishes externally after explicit user confirmation.

Installers should treat this as a VC research drafting aid, verify cited sources and financial assumptions before acting, and only connect or authorize ima publishing when they intend content to leave the chat and understand the target visibility.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill’s trigger keywords are broad enough to match common investment-related conversation such as ‘项目搜寻’, ‘初筛’, or ‘是否值得投’, which can cause the skill to activate when the user did not explicitly intend to invoke it. Unintended activation can lead to unnecessary use of specialized instructions, incorrect workflow selection, or accidental preparation of outward-facing content, especially in mixed business conversations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.