Back to skill

Security audit

Baidu File Translate

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Baidu document-translation helper, but users should understand that translating a file means sending its contents to Baidu’s service.

Install only if you are comfortable using Baidu's document translation service and the @bdtrans/trans-cli npm tool. Do not submit confidential, regulated, or customer documents unless your organization allows that data to be processed by Baidu.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger/description is broad enough to activate on many generic translation requests involving uploaded files, increasing the chance the skill is invoked without a clear user expectation that a third-party document translation service will be used. In this context, overbroad routing matters because the skill handles whole documents and sends them off-platform, which can expose sensitive content through unintended activation.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill description does not clearly disclose that uploaded documents are transmitted to Baidu's external translation service, which is a material data-handling fact. Because this skill processes full files that may contain confidential or regulated information, lack of upfront disclosure can lead to privacy, compliance, and trust failures if sensitive documents are sent off-platform without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.