Back to skill

Security audit

查询Mttr/事件量/Ai提效

Security checks across malware telemetry and agentic risk

Overview

This is a simple security-metrics query skill with no executable code; its main caveat is that ambiguous questions use built-in department and time defaults.

Before installing, make sure users understand that ambiguous metric questions will default to Information Security Department and the current week. In sensitive environments, configure the surrounding data-access controls so the skill can only return metrics the requester is allowed to see, and consider asking users to specify department and time range explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill uses broad fallback triggers like '若用户无主语、无限定词' and example queries such as '本周mttr多少' or '最近事件量变化怎么样', then silently defaults to querying a specific department and time range. This can cause overbroad invocation and misleading results, especially when the user did not intend the default department, leading to unauthorized or incorrect disclosure of department-specific security metrics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.