Back to skill

Security audit

员工XXX的相关案件查询

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable SOP, but it can expose sensitive employee case records beyond its stated role-based scope.

Install only if users already have authorization to access these employee case records and the workflow is tightened to structured role fields or separately approved for broader investigative text search. Consider masking responsible-person details unless they are necessary for an authorized case review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill claims to query cases where the employee is the processed/reported person, but it also performs a broad text search across title, summary, description, and content for the employee's name. This expands access beyond the declared purpose and can surface unrelated sensitive case records merely because a name appears in free text, creating an overcollection and privacy exposure risk.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The SOP says it does not apply to cases where the employee is the responsible person, yet the workflow returns detailed case data including the 'responsible person' field after a broadened search. That contradiction can reveal out-of-scope personnel associations and indirectly enable users to infer or enumerate cases involving the employee in disallowed roles.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.