Back to skill

Security audit

Sustoiclab Think Framework思考框架工具箱 · Su's StoicLab

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese structured-thinking skill with no executable code, external access, persistence, or hidden high-impact behavior.

Install this if you want a Chinese-language structured thinking assistant. Expect it to guide you through frameworks step by step and ask for confirmation before modules; review outputs as advisory analysis, not final decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is entirely written as a Chinese-only interaction flow and explicitly provides Chinese prompt scripts without offering a user language choice or documenting that the skill is locale-specific. This can cause the agent to respond in an unexpected language, degrading usability, consent, and reliability for users who operate in other languages; in safety-critical or compliance-sensitive contexts, misunderstanding the output could materially affect user decisions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are very broad conversational phrases like '太多事', '忙不过来', and '先做什么', which commonly appear in ordinary user messages. That increases the chance this skill is invoked unintentionally, causing routing errors and potentially displacing a more appropriate skill or response path.

Vague Triggers

Medium
Confidence
93% confidence
Finding
模块D包含“ 不懂、不清楚、不明白、搞不懂、困惑、迷茫、没思路、没头绪 ”等高度日常化、低特异性的触发词,会把大量普通求助或泛化问题吸入“多维思考”模块。这会造成路由过度匹配,削弱模块隔离与用户意图识别准确性,在多技能环境下可被用来操纵路由结果。

Vague Triggers

Medium
Confidence
92% confidence
Finding
模块E使用“太多事、忙不过来、瞎忙、没效果、先做什么、怎么提效”等宽泛表述作为触发依据,覆盖了大量非目标场景的常见表达。这会使效率聚焦模块在缺少明确优先级/资源分配语义时被误激活,导致路由偏斜并可能掩盖本应进入其他分析模块的请求。

Vague Triggers

Medium
Confidence
89% confidence
Finding
“最后用语义理解兜底”允许模型在关键词不足时自由解释用户输入,但文档没有给出边界、拒绝条件或校验机制。这种开放式兜底会引入不可预测的路由决策,容易被模糊措辞或提示操纵放大,降低整体可控性。

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.