Back to skill

Security audit

免费版

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only content repurposing skill that drafts platform-specific posts and does not install code, persist data, or auto-publish content.

Install this if you want a drafting assistant for multi-platform content. Review every generated post and translation before publishing, avoid providing private or regulated material unless you are comfortable sending it to your configured AI provider, and do not share API keys or account credentials through Telegram or other off-platform support.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains broad, common phrases such as "repurpose," "adapt for," "改写," and "多平台," which can match ordinary user requests outside the intended scope. This can cause the skill to activate unexpectedly and override user intent, leading to unsolicited transformation of content, cross-platform generation, or accidental processing of sensitive text pasted into a general conversation.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The rules force platform-specific language output, including automatic translation into English or Chinese, even when the user did not request translation or multilingual handling. This can expose user content to unintended transformation, create privacy/compliance issues for sensitive text, and produce outputs the user did not authorize or cannot verify accurately.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill description states that Twitter and LinkedIn outputs are automatically translated/adapted into English, but it does not indicate that this behavior is optional or requires explicit user consent. That can cause unintended cross-language publishing, loss of user control over output language, and accidental disclosure or misrepresentation if users expected same-language adaptation only.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "帮我一稿多发" is broad and lacks clear scoping, which can cause the skill to activate in unintended contexts or on ambiguous user input. In an agent environment, overly generic invocation phrases increase the chance of accidental execution and unexpected content transformation behavior, especially when the skill appears designed for automatic multi-platform rewriting.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
Hard-coding that the Twitter Thread output "is in English" removes user choice over language and may cause the skill to produce content in a language the user did not request. This is primarily a safety and UX control issue rather than a direct security exploit, but it can still lead to unauthorized or misleading output transformations in multilingual workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are very broad, natural-language requests such as '帮我把这段内容一稿多发' and similar variants. In an agentic environment, overly generic triggers can cause accidental activation on ordinary conversation or unrelated content-processing tasks, leading to unintended data handling or unexpected behavior.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The usage examples show the skill being invoked with common rewriting requests but do not define clear activation boundaries. This increases the chance that routine editing requests are interpreted as permission to perform broad multi-platform transformation, which may process more user content than intended.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The documentation states that Twitter Thread and LinkedIn outputs are English by default, without indicating that users can opt in or override the language. This can cause unintended language conversion, which is a policy and user-intent risk because the system may transform or publish content in a language the user did not request.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The FAQ says the skill will automatically translate content for Twitter and LinkedIn, but it does not mention user confirmation. Automatic language switching can misrepresent user intent, introduce translation errors, and create downstream publishing mistakes if users assume outputs remain in the original language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.