Back to skill

Security audit

Dawn Office Suite

Security checks across malware telemetry and agentic risk

Overview

This is a broad Office/PDF document-assistance skill, but its artifacts contain no executable code, hidden persistence, credential use, or data-sharing instructions.

Installers should treat this as a general-purpose office document helper. Use normal caution with untrusted documents and avoid asking it to run macros, follow external links, or perform credentialed cloud actions unless those behaviors are explicitly reviewed and user-directed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises very broad document-processing capabilities across Word, PowerPoint, Excel, PDF, and general Office workflows without defining trigger boundaries, input constraints, or disallowed operations. In an agent setting, this can cause over-invocation, unsafe handling of untrusted files, or execution of risky document-manipulation requests beyond the author's intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.