Back to skill

Security audit

流梦 AI 小说创作助手 FlowDream AI Novel Writer

Security checks across malware telemetry and agentic risk

Overview

This is a plain markdown fiction-writing skill with purpose-aligned local story files and no evidence of hidden commands, credential access, or data exfiltration.

Install if you want an agent to help manage fiction projects with local markdown notes. Be aware it may activate on broad writing-related phrases, and it may read or update story files in the current project when you ask it to continue or review a story.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger text is overly broad because it includes many loosely related prompts and an open-ended 'or similar phrases' clause, which can cause the skill to activate when the user did not actually request novel-writing help. In an agent environment, unintended invocation can override more appropriate skills or route sensitive user content into an irrelevant workflow, creating prompt-scope confusion and reducing user control.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage guidance enumerates broad keywords without clear scope boundaries, so ordinary discussion containing terms like outline, character setting, or polishing could spuriously match and invoke the skill. This is dangerous in multi-skill systems because ambiguous activation increases the chance of misrouting tasks, context pollution, and the assistant following the wrong operational instructions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.