Back to skill

Security audit

zhihu-hot-article-engine

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Zhihu writing-method skill with no executable code, credential use, posting automation, or hidden data access.

Install this if you want an agent to draft or optimize Zhihu-style Chinese long-form content. Review generated claims, citations, credentials, and engagement language before publishing so it does not overstate expertise, fabricate sources, or use platform tactics you are uncomfortable with.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill prescribes Chinese-only output conventions and specific Zhihu-native phrasing without stating that this should be conditional on the user's requested language or target platform. In an agent setting, this can override user intent, cause unwanted language switching, and reduce transparency by making the model follow hardcoded presentation constraints rather than the user's explicit preferences.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.