Back to skill

Security audit

适童化装修指南

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese child-room renovation guidance skill with no executable code, persistence, credential access, or hidden data flow.

Install only if you want a strongly opinionated Chinese-language renovation advisor for child rooms. Treat its health and material-safety claims as consumer guidance, not professional environmental, medical, or legal advice, and verify important renovation decisions independently.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains broad consumer and household phrases such as '儿童房', '宝宝房', and '母婴装修' that can match many ordinary renovation or parenting queries, causing the skill to activate outside a clearly intended scope. Over-broad invocation increases the chance that users receive rigid, one-sided guidance without explicitly choosing this skill, which is a security and trust issue in agent routing.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill content is entirely written to operate in Chinese and does not provide any user-choice mechanism for language. This can override user preference or system context, leading to confusing or inaccessible responses, especially in multilingual environments where language coercion may impair informed use of the skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.