Back to skill

Security audit

装修水电避坑指南

Security checks across malware telemetry and agentic risk

Overview

This is a renovation water-and-electrical advice skill with static reference files and no evidence of hidden execution, data access, persistence, or exfiltration.

Installers should treat this as practical homeowner guidance, not a substitute for local building codes or qualified electrical/plumbing work. The main caveat is that broad triggers may invoke the skill for general household questions, so review answers for renovation context before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes short, common terms such as '水电', '水路', '电路', and '防水' that can appear in many unrelated conversations. This can cause unintended activation of the skill, leading to irrelevant guidance being injected into chats and reducing trust in routing accuracy, though it does not directly create code-execution or data-exfiltration risk.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Several triggers in this range are generic household or infrastructure terms like '插座', '开关', '防水', '总阀', '角阀', and '路由器' without requiring explicit装修水电 context. In a broad assistant environment, these terms may match ordinary troubleshooting or purchasing questions and invoke the skill inappropriately, creating prompt-routing noise and possible misleading domain-specific advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.