Back to skill

Security audit

去AI味 Humanizer

Security checks across malware telemetry and agentic risk

Overview

This is a text-editing skill that does what it says, with a minor caution that some trigger phrases are broad enough to activate during ordinary polishing requests.

Before installing, be aware that this skill may activate for general polishing or "humanize" requests and may make substantive stylistic changes. Use explicit prompts when you want AI-pattern removal, and review edits before applying them to academic, resume, business, or literary documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation examples are broad enough to overlap with ordinary editing and rewriting requests, so an agent may trigger this skill in situations where the user did not explicitly ask for AI-style removal. Because the skill performs substantive style transformation, overbroad routing can cause unintended content modification, especially for academic, professional, or literary text where preserving author intent matters.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger set includes broad editing phrases that can match ordinary user requests, causing the skill to activate outside its intended niche. This is dangerous because the skill has Write/Edit capabilities and explicitly tries to alter text style, so accidental invocation can lead to unintended modification of user content or incorrect routing of benign requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The English trigger 'humanize' is broad and commonly used in ordinary conversation, making accidental activation likely. In a public skill with editing tools, this can reroute unrelated requests into content-rewriting behavior and produce unwanted transformations or file edits that the user did not intend.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
92% confidence
Finding
The trigger '润色' is extremely short and broadly maps to common requests for polishing or editing text. Because this public skill can write and edit content, such a generic trigger increases the chance of unintended activation and unauthorized or surprising changes to user material in workflows where a more general editor would have been expected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.