Back to skill

Security audit

AI Short Drama Toolkit

Security checks across malware telemetry and agentic risk

Overview

This is a coherent short-drama creation guide with no executable code or hidden system access, though users should be careful with voice rights and third-party AI services.

Install this if you want a Chinese AI short-drama production reference. Avoid uploading confidential scripts, private audio, or identifiable voice likenesses to third-party AI tools unless you have consent, rights clearance, and understand the provider’s data retention and commercial-use terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README shows very broad natural-language examples that imply the skill will automatically choose an internal mode based on loosely phrased user input. Without documented trigger boundaries or disambiguation rules, a caller can unintentionally invoke the wrong workflow, causing prompt/template misuse, unexpected tool selection, or exposure of monetization/production guidance when a narrower action was intended. In this skill, that ambiguity is more meaningful because it advertises multiple distinct capabilities under one interface.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation logic is broad enough that ordinary user requests about making a short drama could automatically invoke this skill without clear user intent or confirmation. That can cause incorrect routing, unexpected behavior, and prompt/context injection into unrelated conversations, especially in an agent environment where skills are selected automatically.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The listed trigger phrases are ambiguous and lack scope boundaries, so the agent may activate this skill for loosely related requests like prompts, tools, monetization, or story ideas that do not actually require the full short-drama workflow. In multi-skill systems, this increases the chance of misfires, unintended file reads, and cross-skill interference that can degrade safety and reliability.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow explicitly recommends AI voice generation and preserving fixed voice IDs, but it omits any warning about consent, voice ownership, impersonation risk, or privacy implications of uploading scripts and voice data to third-party services. In a content-production skill, this omission can lead users to clone or use voices without authorization, or to expose personal/sensitive audio and dialogue to external platforms under unclear retention and licensing terms.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.