Back to skill

Security audit

Video Script Writer

Security checks across malware telemetry and agentic risk

Overview

This skill is a short-video script writing helper, and the artifacts show no malware, credential use, persistence, or destructive behavior.

Safe to install for Chinese short-video script drafting. Be aware it may activate on broad content-writing prompts; users or the publisher may want to narrow triggers to explicit short-video script, hook, platform, or duration requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s activation criteria are very broad and overlap with ordinary writing, brainstorming, and content-planning requests. This can cause unintended invocation, routing user requests into this skill when a more general assistant response would be appropriate, creating prompt-scope confusion and reducing user control.

Vague Triggers

Low
Confidence
88% confidence
Finding
The trigger '告诉我主题和目标平台' is too generic because many harmless content discussions include a topic and platform without intending to invoke a specialized skill. This increases the chance of accidental skill activation and misclassification of user intent.

Vague Triggers

Low
Confidence
86% confidence
Finding
The hook-generation trigger is framed as a generic ideation request and can easily match normal brainstorming prompts unrelated to skill use. In an agent environment, such ambiguity can lead to over-triggering, unnecessary file/tool reads, or incorrect routing of the user’s request.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.