Back to skill

Security audit

论文去AI味(最佳)

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese text rewriting service, but its auto-invocation setting is too broad for a tool that can disguise AI-written or academic text.

Install only if you want a third-party AI Skills service to process the text, files, or URLs you provide. Prefer explicit invocation, avoid confidential or regulated content unless external processing is approved, and do not use it to bypass academic, workplace, platform, or disclosure rules about AI-generated writing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation but does not define any trigger constraints, examples, or scoping conditions, which increases the chance that it will be auto-selected in contexts the user did not intend. Because this skill rewrites content to reduce detectable AI-writing traits, accidental or overly broad invocation could inappropriately transform sensitive, academic, or policy-relevant text without clear user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.