Back to skill

Security audit

社区热点痛点分析

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed community-analysis prompt skill for turning Reddit/forum machinery discussions into FridayParts content ideas, with only mild routing and language-scope caveats.

Install this if you want a Chinese-language FridayParts workflow for analyzing machinery community posts. Use it with Reddit/forum data you intend to analyze, watch for accidental activation on generic “pain point” or “topic analysis” prompts, and review outputs before publishing, especially any repair or emissions-compliance content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad terms like '社区分析', '用户痛点', and '选题分析' that can match many unrelated user requests, causing the skill to activate outside its intended Reddit/forum-mechanics scope. Overbroad activation can route general conversations into a prompt that steers outputs toward FridayParts-specific content generation, creating prompt-scope hijacking and unintended data handling risks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'Use when' description is ambiguous and broad, inviting invocation for generic 'forum hot topics' or 'topic analysis' rather than the narrow intended use of clustering imported mechanical-community data. In agentic environments, vague activation conditions can misapply this skill to unrelated inputs, increasing the chance of irrelevant instruction takeover, data leakage across workflows, or brand-biased output where it does not belong.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase "用户痛点" is broad enough to match many unrelated requests about customer pain points, user research, or generic product analysis. This can cause accidental skill activation and route user data or prompts into a domain-specific workflow the user did not intend to invoke.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "选题分析" is highly generic and can apply to many ordinary content-planning requests unrelated to this skill. Overbroad activation increases the chance of unintended invocation, wrong tool selection, and leakage of context into an inappropriate analysis pipeline.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
Mandating Chinese output without user choice can override user expectations and system-level language preferences, reducing usability and potentially causing misunderstanding in multilingual workflows. While not a direct security flaw, it is a prompt-scope weakness that can lead to improper handling of user requests or downstream automation failures when another language is expected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.