Back to skill

Security audit

五维思维分析 · Su's StoicLab

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed conversational framework for structured analysis, with no code execution, data access, persistence, or hidden behavior.

Install this if you want a structured Chinese-language guide for analyzing complex topics. Be aware it may activate for broad analysis requests, so for specialized medical, legal, financial, or safety-critical decisions, use it only as a thinking aid and rely on appropriate expert guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
88% confidence
Finding
The stated scope covers nearly any complex event, social phenomenon, historical issue, or life decision, making the activation boundary ambiguous. While not directly enabling code execution or data exfiltration, this broad applicability increases the chance of accidental invocation in contexts where the framework is unsuitable or may oversimplify high-stakes decisions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The stated scope covers nearly any complex event, social phenomenon, historical issue, or life decision, making the activation boundary ambiguous. While not directly enabling code execution or data exfiltration, this broad applicability increases the chance of accidental invocation in contexts where the framework is unsuitable or may oversimplify high-stakes decisions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions include very common phrases such as '你帮我分析一下吧' and broad uncertainty language like '我不知道' or '信息不够'. In a conversational skill, this can cause unintended activation of the deeper analysis flow in many normal chats, expanding the skill’s influence beyond user intent and potentially steering conversations in ways the user did not explicitly request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.