Back to skill

Security audit

Tech Blog Writing

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward technical blog writer that creates local HTML files and does not request network, credential, or privileged access.

Install this if you want technical article requests to be turned into standalone HTML files. Before using it in a directory with important files, check the generated filename and avoid overwriting an existing file with the same slug.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill advertises broad trigger phrases such as generic requests to 'write' or 'produce' a blog post, which can cause overbroad activation on normal writing tasks. This is dangerous because it may steer unrelated user requests into this skill's workflow, including its file-writing behavior, without clear user intent to invoke it.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to render content into HTML and write it to a file, but it provides no requirement to obtain user confirmation or disclose that a filesystem modification will occur. This is dangerous because it can lead to unintended file creation, overwriting, or persistence of user-provided content on disk when the user may have expected only a conversational response.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.