Back to skill

Security audit

Humanizer Academic ZH

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only Chinese academic rewriting skill that is openly aimed at making text look less AI-generated, so it needs academic-integrity caution but does not show hidden code, data access, persistence, or technical compromise behavior.

Install only if this type of rewriting is allowed by your school, publisher, employer, or disclosure rules. Use it for legitimate editing of your own work, avoid using it to misrepresent authorship or bypass AI-use policies, and inspect the remote GitHub content before running the README's npx, git, or curl install commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README instructs users to paste the entire system prompt into a model so it remains active for any conversation, without clear scope or trigger constraints. In a skill explicitly designed to rewrite text to remove AI indicators and lower AIGC detection, this broad activation increases the chance of unintended application, overreach, and misuse across unrelated conversations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage section says that once activated, users can directly send text for processing without additional boundaries, which makes the skill effectively always-on within the session. Given the skill's purpose of reducing detectable AI-writing patterns, this lack of gating makes misuse easier and raises the likelihood that the model will transform content in contexts where it should instead seek clarification or refuse.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description is broad enough to activate on common phrases like '帮我改改这段', which can cause the skill to engage outside its intended narrow context. Because the skill’s purpose includes removing 'AI味' and lowering AIGC detection rates, accidental triggering increases the chance of policy-evading rewriting being applied to benign editing requests.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill is hard-coded as a Chinese-language academic rewriting workflow without indicating user choice or fallback behavior. While not directly a security exploit, forced locale behavior can override user intent, increase unintended activation, and reduce transparency about how content will be transformed.

Ssd 2

Medium
Confidence
98% confidence
Finding
The skill is explicitly designed to '去除AI味' and '降低AIGC检测率' in academic writing, which is an evasion objective rather than ordinary proofreading. In the academic context, this can facilitate misrepresentation of authorship, bypass institutional AI-use controls, and enable plagiarism or undisclosed machine-generated submissions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.