Back to skill

Security audit

Inspiration / Case Figure Guide

Security checks across malware telemetry and agentic risk

Overview

This is a text-only workflow skill for designing research-paper figures, with disclosed image-generation use and no evidence of hidden execution or data theft.

Install this only if you are comfortable with a structured, Chinese-formatted workflow and with using an image-generation provider for candidate figures. For confidential or unpublished papers, provide only sanitized excerpts or use an approved provider. Also verify that installation does not grant actual purchase, payment, or crypto permissions despite the unrelated marketplace tags.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill's control flow depends on an undefined 'first trigger' state, which creates ambiguity about when restrictive startup behavior applies. In agent systems, unclear state boundaries can be exploited or accidentally bypassed, causing the model to skip intended safety or sequencing constraints and execute later-stage behavior prematurely.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
Forcing Chinese-language response sections regardless of user preference can cause instruction confusion, reduce transparency, and increase the chance that users miss important constraints or review content incorrectly. While not directly enabling code execution or data exfiltration, it undermines reliable human oversight and can lead to unsafe or noncompliant interaction flows.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The example package embeds Chinese-language workflow text and next-step prompts without any indication that the user requested Chinese or that locale selection is configurable. This can override or bias downstream agent behavior, causing unexpected language switching, reduced usability, and possible misinterpretation of safety-critical review content for users who do not read Chinese.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The example startup turn hard-codes Chinese-language interaction for the workflow and suggested next steps without indicating that language should follow the user's preference. This can degrade usability, cause misunderstandings in safety-critical or technical prompting, and effectively exclude users who cannot read Chinese from understanding what the agent is doing or consenting to the workflow.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The example content is entirely in Chinese and steers the interaction into Chinese without indicating that the user may choose another language. In a general-purpose agent skill, this can degrade usability, cause misunderstanding of workflow/state instructions, and create accessibility and trust issues for users who do not read Chinese.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The example turn is written entirely in Chinese and presents the workflow, defaults, and suggested next prompts without offering any user-language negotiation. This can cause incorrect or inaccessible interactions for users who do not read Chinese, leading the agent to follow a language constraint the user did not request and increasing the chance of misunderstanding or misuse of the skill.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The starter messages are written entirely in Chinese and implicitly steer interaction into Chinese without indicating that other languages are supported. This can exclude users, cause misunderstanding, and create usability/accessibility issues, but it does not by itself introduce direct code-execution or data-exfiltration risk.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The workflow hard-codes Chinese section headings and a Chinese next-prompt string for every text reply, without providing a language-negotiation path. This can override the user's preferred language, reduce usability, and create misleading or inaccessible outputs in multilingual contexts; while not a code-execution issue, it is a real prompt-safety and policy-compliance weakness.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The template mandates a Chinese-language footer in every TEXT_ONLY reply (`当前状态与产物` and `全部步骤与当前位置`) without any indication that this should depend on user preference or locale. This can override the user's requested language, degrade usability, and create prompt-level instruction conflicts that make the agent behave unexpectedly or disclose internal workflow metadata in an inaccessible form.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.