Back to skill

Security audit

If Book Could Speak

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed book-video generation workflow with external media and TTS steps that fit its stated purpose.

Install only if you are comfortable with the skill using external search, image generation, TTS services, dependency/model downloads, and local video output. Prefer environment variables over storing API keys in a skill directory, and review any referenced scripts or assets before running them because the submitted artifact contains only SKILL.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad and include generic terms like '做读书视频' and '书会说话', which may cause the skill to activate for common book-related or video-generation requests the user did not intend for this workflow. In an agent ecosystem, overbroad activation can route user content into unnecessary web search, API calls, and media-generation pipelines, increasing risk of unintended actions and data handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.