Back to skill

Security audit

Prompt Alchemist-提示词炼金术

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-improvement skill with broad but disclosed activation wording and no evidence of tool use, credential access, persistence, or data exfiltration.

Install this if you want help improving prompts. Be aware it may be selected for broad prompt-optimization requests or pasted prompt-like text, so invoke it when you clearly want rewriting or diagnosis and avoid using it as the default handler for arbitrary pasted content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill’s activation logic is overly broad, including generic phrases and automatic triggering when users paste text. This can cause the skill to activate unintentionally in unrelated conversations, leading to prompt rewriting or instruction injection into contexts where the user did not explicitly request it.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal