Back to skill

Security audit

Article2Book

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a legitimate local content-planning tool, but users should only point it at folders they are comfortable having read and summarized into local output files.

Install if you want a local assistant to read and reorganize a selected folder of writing materials. Use a dedicated folder with only intended documents, redact client or personal information first, and review or delete the generated `书稿策划输出/` and `processed/` files if they contain sensitive summaries or snippets. The unsupported crypto/purchase metadata should be corrected by the publisher, but the artifacts themselves do not show that behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger description is broad and covers many loosely related scenarios such as turning mixed content assets into books, courses, manuals, or knowledge bases. Overbroad activation can cause the wrong skill to run on sensitive or irrelevant material, leading to unnecessary file access, analysis of unintended documents, or accidental output generation. The skill context makes this somewhat more concerning because it is designed to inspect whole directories of content.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill defaults to creating a `书稿策划输出/` directory under the source directory and writing multiple files, but it does not prominently warn the user that local files will be created and existing workspace contents may be affected. This creates a real risk of unintended persistence of sensitive summaries, metadata leakage, repository pollution, or accidental overwrite/confusion in user-controlled directories. Because the skill's normal workflow includes writing derived content from potentially confidential source materials, the lack of explicit warning and opt-in increases the danger.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.