Back to skill

Security audit

Privacymask 数据脱敏与隐私保护助手

Security checks across malware telemetry and agentic risk

Overview

This privacy-masking skill is mostly aligned with local file redaction, but it also promotes broad skill installation and uses under-scoped automatic routing for file-changing actions.

Install only if you are comfortable with a skill that can process local files and write masked copies or reports. Avoid using the matrix-install phrase unless you intentionally want additional unrelated skills, and review output locations and generated reports because they may still contain sensitive metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The skill is presented as a privacy/data-masking tool, but it also promotes installing a broader skill matrix and links to unrelated skills. This expands the effective trust boundary and can socially engineer users into installing additional capabilities unrelated to the current task, increasing attack surface and enabling privilege creep.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad terms such as 'PII', 'mask', '敏感信息', and especially '安装完整技能矩阵', which can match ordinary conversation or requests outside the narrow scope of this skill. Overbroad activation can cause the assistant to invoke file-processing or installation-related behavior unexpectedly, which is risky in a tool that operates on local files.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Using '安装完整技能矩阵' as a trigger inside a privacy tool is scope-inappropriate and may initiate acquisition of additional skills beyond what the user expects from a desensitization assistant. In context, this is more dangerous because the document explicitly states shared MCP infrastructure and one-click bulk installation, which can be used to escalate capabilities through ambiguous phrasing.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill advertises batch processing and report export, which inherently involve writing files, but the documentation does not give clear warnings about overwrite behavior, destination safety, naming collisions, or handling of sensitive outputs. For a privacy tool, generated masked copies and reports can still contain sensitive metadata or be saved to unsafe locations if users are not explicitly warned.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The natural-language router defaults to the state-changing `scan_and_mask` action and maps broad keywords directly to destructive or privacy-impacting operations without any confirmation step. In a skill that can modify files or recursively process directories, ambiguous user text can cause unintended masking actions, leading to accidental data alteration or bulk changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.