Back to skill

Security audit

WorkBuddy Tuner 卡顿诊断与性能优化助手

Security checks across malware telemetry and agentic risk

Overview

This WorkBuddy tuning skill is purpose-aligned but needs Review because it advertises system-changing optimization, monitoring, migration, and install workflows while also making contradictory low-risk and privacy claims.

Install only if you are comfortable giving the skill broad local performance-monitoring and tuning authority. Before using optimization, migration, recovery, automated scan, or skill-matrix installation features, confirm the exact files, sessions, processes, and directories affected; keep dry-run enabled until reviewed; and avoid granting access to credentials or private session data unless the host provides clear containment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill describes file read/write behavior such as cache cleanup, backups, archiving, and migration, but declares no permissions or equivalent capability disclosure. This creates a dangerous transparency gap: users and the host platform may trust the skill as low-risk while it can perform state-changing filesystem actions, increasing the chance of unauthorized or unsafe modification of user data.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The document claims the skill does not perform system-level operations, yet elsewhere it advertises cache cleanup, process management, model reload, optimization execution, and scan-frequency changes. This contradiction can mislead users into approving a skill under false assumptions, reducing informed consent around actions that may alter system state, terminate processes, or affect application behavior.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The privacy statement says no device information is collected, but the skill's own monitoring features rely on collecting memory, CPU, disk, network, process, and performance telemetry. Even if data stays local, the statement is materially inaccurate and may cause users to disclose or authorize monitoring they would otherwise decline; if any reporting leaves the device, the privacy impact increases further.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The run() method accepts an arbitrary tool_name and forwards it to dispatch_tool with full state automatically attached. That creates a broader invocation surface than the skill description advertises, and if an attacker or prompt injection can influence tool_name, they may reach unintended tuner_original.* adapters or other dispatchable tools with sensitive state.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are very broad and match ordinary help requests such as '电脑变慢了', '清理缓存', or '网络慢', which can cause the skill to activate in contexts where the user did not intend to invoke a high-impact optimization tool. In a skill that discusses cleanup, migration, monitoring, and optimization actions, overbroad activation increases the risk of accidental invocation and unintended access to system data or state-changing workflows.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The top-level description promotes one-click optimization, self-inspection, backup/export, migration, and reinstall-recovery workflows without equally prominent warnings about data loss, service interruption, credential handling, or system impact. Because these are high-consequence operations in a performance-tuning skill, understated risk communication can lead users to authorize sensitive actions without understanding the consequences.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The orchestrator automatically injects the full state into downstream tool calls without any per-call minimization or visible disclosure boundary. In a tuning skill, that state may include system, session, audit, or recovery-related data, so unnecessary propagation increases privacy and data exposure risk if downstream tools log, transmit, or misuse it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.