Back to skill

Security audit

影视解说生成

Security checks across malware telemetry and agentic risk

Overview

This is a content-only Chinese film commentary writing skill with no evidence of hidden execution, data access, persistence, or credential use.

Installers should expect this skill to produce Chinese film-commentary planning content. Review its output for copyright and platform suitability, especially BGM licensing, but the artifact does not show risky local access or hidden behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are broad enough to match generic requests about scripts, subtitles, BGM, or editing suggestions, which can cause the skill to activate when the user did not explicitly ask for this workflow. Unintended activation can override more appropriate skills, produce irrelevant output, and increase the chance of mishandling user intent in multi-skill environments.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written to operate in Chinese throughout and does not provide a user-language negotiation path or justify why output must be Chinese. In a multilingual environment, this can lead to user confusion, inaccessible output, and incorrect fulfillment of requests when the user expects another language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.