Back to skill

Security audit

Story Short Analyze

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed short-fiction analysis skill that reads user-provided story text and writes local analysis outputs, with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable with the skill saving a local copy of the story text and generated analysis under `拆文库/{书名}/`. Use explicit commands like `/story-short-analyze` when possible, and provide paths only to files you intend the agent to read.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill registers multiple very broad natural-language trigger phrases such as '拆短篇', '分析这篇短篇', and similar variants that are close to ordinary user requests. This can cause accidental or over-broad invocation, especially when a user is discussing analysis conceptually rather than intentionally invoking the skill, leading to unintended file operations and processing of local content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.