Back to skill

Security audit

Ai Content Polish

Security checks across malware telemetry and agentic risk

Overview

This is a transparent text-only writing skill, but it is explicitly built to make AI-generated Chinese text look less AI-generated and has no guardrails against deceptive use.

Review this carefully before installing. It is suitable only for transparent readability and style review of Chinese text. Do not use it to hide AI authorship or bypass disclosure, academic integrity, publication, moderation, provenance, or platform rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README advertises very broad natural-language triggers such as checking whether text has 'AI味', making text '更自然', and references to '反检测' and 'AI watermark' without clear guardrails. In this skill's context, that creates a real misuse risk because the stated purpose is to make AI-generated content look less detectable, which can enable academic dishonesty, deceptive marketing, moderation evasion, or bypassing provenance/detection systems.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are broad enough to activate on common editing or writing-quality requests, not just explicit AI-trace analysis. This can cause the agent to apply a de-detection/evasion-oriented skill in ordinary contexts, increasing the chance of misuse and unintended assistance with concealing AI authorship.

Ssd 2

Medium
Confidence
96% confidence
Finding
The skill explicitly markets itself for making AI-generated text appear human-written and even references '反检测' and 'AI watermark' contexts. That materially facilitates deception, evasion of provenance or detection systems, and misrepresentation in academic, commercial, or platform-governed settings.

Ssd 2

Medium
Confidence
97% confidence
Finding
The core tagline and listed functionality directly instruct rewriting text so it no longer looks AI-authored, which operationalizes concealment rather than neutral proofreading. In context, the detailed scoring and rewrite workflow make the skill more dangerous because they provide a repeatable method for evading AI-origin scrutiny at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.