Back to skill

Security audit

小红书种草笔记(自动配图)

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real article-and-image generation skill, but it can implicitly send user prompts, brand details, and profile context to an external AI Skills API under broad activation wording.

Install only if you are comfortable sending prompts, drafts, audience details, keywords, brand requirements, and possible profile context to ai-skills.ai using your API key. Avoid confidential drafts, customer data, regulated personal data, secrets, or proprietary brand material unless that provider is approved for your use, and prefer explicit confirmation before each run or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
84% confidence
Finding
Overly broad trigger phrases can cause the agent to invoke this skill in situations beyond the user's intent, sending unrelated prompts or sensitive drafting material to the external service. Because this skill transmits content to a third-party API, accidental activation increases privacy and data-handling risk beyond a mere usability issue.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage guidance is broad and lacks constraints, making it more likely the orchestration layer will route diverse requests into this skill without clear necessity. In this context, broad routing is security-relevant because the skill forwards user content to an external API without prominently warning the user, amplifying the chance of inadvertent data disclosure.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The documentation does not clearly warn that supplied inputs will be sent to an external API, so users may provide confidential drafts, business plans, personal data, or internal content under the false assumption of local processing. Lack of disclosure undermines informed consent and can lead directly to privacy, confidentiality, and compliance violations.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrase "自动公众号和种草?" is broad and underspecified, so the skill may be invoked for a wide range of loosely related content-generation tasks without clear user intent boundaries. In an execution-mode LLM skill, ambiguous routing can cause accidental activation, inappropriate handling of unrelated prompts, and expansion of the skill's effective permission and data-processing scope beyond what users expect.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.