Back to skill

Security audit

装修流程不踩坑

Security checks across malware telemetry and agentic risk

Overview

This is a home-renovation advice skill with local markdown reference files and no executable, network, credential, or persistence behavior.

Before installing, consider that it may activate on common renovation questions and answer in a strong advisory style. It does not appear to access private data or run code, but renovation safety, legal, and building-code details should still be checked against local professionals and current local rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list contains broad, natural-language phrases such as '装修第一步', '装修下一步做什么', and '装修要多久', which can match ordinary conversation outside an explicit skill-invocation context. This can cause unintended activation, leading the assistant to switch behavior unexpectedly and answer from the skill when the user did not clearly request it.

Vague Triggers

Low
Confidence
72% confidence
Finding
The skill defines many triggers but does not specify activation boundaries, disambiguation logic, or when the assistant should refuse to activate. Ambiguous invocation scope increases the chance of accidental routing, especially for short phrases that may appear in unrelated planning or household discussions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.