Back to skill

Security audit

Abnt Citation

Security checks across malware telemetry and agentic risk

Overview

This is a simple ABNT citation-formatting skill with no executable code, network behavior, persistence, or hidden data handling found.

Install this if you want help formatting or checking ABNT references. Be aware it may respond in Brazilian Portuguese and may activate on some broad formatting/citation requests, but no artifact evidence shows code execution, exfiltration, destructive behavior, or hidden persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is broad enough to match generic formatting requests involving source data, which can cause the skill to activate outside its intended scope. This is not a code-execution issue, but it can lead to incorrect routing, user confusion, and accidental handling of requests that are not specifically about ABNT references.

Vague Triggers

Low
Confidence
90% confidence
Finding
Using 'citação' as a trigger without stronger qualifiers is underspecified because many user intents could involve quotations or citations unrelated to ABNT formatting. In context, this makes unintended invocation plausible, reducing reliability and potentially exposing user content to the wrong skill workflow.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
Mandating Brazilian Portuguese communication without user choice can create a usability and policy issue by overriding user language preference. In this academic formatting context the risk is limited, but it can still degrade accessibility, cause misunderstanding, and mis-handle multilingual user requests.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.