Back to skill

Security audit

critical-writing

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese structured writing workflow that is somewhat rigid but does not show hidden access, code execution, data theft, or destructive behavior.

Install this if you want a Chinese, step-by-step writing assistant that asks setup questions, drafts in stages, critiques through debate, and then rewrites. Avoid enabling it globally if you usually want quick one-shot drafts or non-Chinese output, because its own instructions prefer the full workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Confidence
93% confidence
Finding
The skill declares that it 'must' be used for very broad writing-related prompts, including generic requests like drafting articles, reports, emails, or posts. This can cause unintended activation over a wide range of normal conversations, overriding user intent and forcing a rigid workflow before responding. In context, this is not code-execution dangerous, but it is a policy/control risk because it can hijack benign requests and degrade safety and usability by imposing unnecessary steps.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill metadata and content fix the workflow to zh-CN without offering language selection or confirming the user's preferred language. If auto-activated, this can produce responses in an unexpected language, causing confusion, miscommunication, and poor user control. In this writing-assistant context the impact is limited, but it becomes more concerning because the same skill already has broad activation criteria, increasing the chance of unintended Chinese-language responses.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The example file and surrounding skill design are entirely in Chinese and present the workflow as mandatory without any visible mechanism to preserve or adapt to the user's language. In a writing skill, forcing a language mismatch can cause unintended disclosure, unusable outputs, or failure to meet user intent, especially in multilingual or compliance-sensitive contexts.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.