docx-generator

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a localized Chinese-language assistant, with no evidence of hidden access, persistence, destructive behavior, or data misuse.

Install this if you are comfortable with a Chinese-first skill. If you need English or multilingual output, check whether the skill supports language override instructions before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The manifest description and the visible skill documentation are written entirely in Chinese, and the examples and generated footer text also assume Chinese output. The file does not state that this skill is China-specific or provide any user opt-in or language selection, which can violate a language/locale policy requiring user choice.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal