Back to skill

Security audit

短视频黄金 3 秒钩子生成器

Security checks across malware telemetry and agentic risk

Overview

This is a short-video hook generator with local usage tracking and optional local monitoring docs, but no evidence of hidden credential access, network exfiltration, or destructive behavior.

Install only if you are comfortable with a local Python-based skill that keeps usage counters and may keep local topic statistics if the optional monitor is used. Avoid entering sensitive private topics, and do not configure the scheduled monitoring task unless you want recurring local reports. The publisher should clarify telemetry retention/opt-out details and fix the inconsistent free-versus-paid wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The '关于' text claims the project is '完全免费', but the implementation enforces a daily limit and includes an upsell path for paid benefits. This is a genuine integrity and trust issue because users are misled about pricing and usage constraints, which can constitute deceptive behavior even though it is not direct code execution or data exfiltration.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document explicitly plans daily automatic collection of usage, conversion, retention, and revenue metrics, but it does not mention user notice, consent, data minimization, retention limits, or a privacy policy. In a commercial user-facing skill, this creates privacy and compliance risk because operators may implement tracking in a non-transparent way, exposing users to undisclosed profiling and the business to regulatory violations.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The deployment guide instructs operators to configure ongoing monitoring and report generation, but it does not present a clear user-facing notice, consent flow, retention policy, or concrete description of what telemetry is stored and for how long. Even if the stated intent is anonymous analytics, undocumented telemetry in a monetized skill can create privacy and compliance risk because users may be monitored without meaningful transparency.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README states that the skill automatically collects usage data and reports it daily, but it does not present this as an explicit opt-in, provide clear consent language, or document controls to disable telemetry. Even if the listed fields are non-sensitive, silent collection and transmission of behavioral data creates a privacy and trust risk, especially in an agent skill context where users may not expect outbound reporting.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly claims it will automatically record usage counts and popular templates, but provides no disclosure about what exact data is collected, how long it is retained, who can access it, or whether any user inputs are logged. This creates a privacy and compliance risk because users may unknowingly provide topic ideas or business information that becomes part of analytics without informed consent or minimization.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:16