Back to skill

Security audit

Typecho Publisher

Security checks across malware telemetry and agentic risk

Overview

This skill is meant to manage a Typecho blog, but the package includes a live-looking blog URL and API token that could let installed agents publish, update, or delete content on that configured site.

Review carefully before installing. Replace or remove the bundled config.json credentials, ensure the token belongs only to your own Typecho site, prefer draft or confirmation-gated publishing, and require explicit confirmation for create/update/delete operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are broad enough to activate on common phrases like '写笔记', '归档', '我的博客', or '更新我的博客', which can cause the agent to invoke a write-capable blog management skill when the user may only be discussing content conceptually. In this skill's context, accidental invocation is more dangerous because the skill can create, modify, and delete remote blog posts using stored credentials, turning ambiguous language into unintended state-changing actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal