Back to skill

Security audit

De-AI Polish

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese writing-polish skill with a disclosed punctuation helper; I found no hidden network, credential, or persistence behavior.

Install this only if you want Chinese drafts edited for a specific anti-AI style. Review changes before publishing, especially for legal, technical, or multilingual text, and use the script's output option or a copy if you need to preserve the original file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The implemented behavior only rewrites punctuation in Markdown files, while the skill manifest says this step must detect and remove AI-style phrasing before content is shown to users. That mismatch can create a false sense of compliance in an automated writing pipeline: downstream systems may believe mandatory de-AI filtering occurred when it did not, allowing prohibited or policy-sensitive output to pass unchanged.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The module documentation explicitly describes punctuation conversion, which conflicts with the broader skill purpose of detecting and removing AI-like phrasing. This documentation/behavior mismatch is dangerous because operators and orchestration code may trust the skill to satisfy a mandatory review step when it actually performs a much narrower, non-equivalent transformation.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill mandates execution before output and assumes Chinese-language punctuation and formatting rules, without checking the user's language or locale. In mixed-language or non-Chinese content, this can silently corrupt formatting, alter meaning, or degrade output quality because processing is forced rather than contextual.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The document prescribes a mandatory stylistic transformation pipeline and frames one writing style as required without clear user consent, applicability limits, or opt-out conditions. In an agent skill context, this can override user intent and systematically alter output tone or meaning, creating integrity and trust risks even though it does not directly enable code execution or data exfiltration.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.