Back to skill

Security audit

Daily Poem

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed poetry helper with optional scheduled poem reminders and no evidence of hidden data access, credential use, or unsafe behavior.

Install this if you want a poem assistant that may respond to broad poem-related prompts. Review the cron commands before enabling scheduled pushes, and use cron list/delete or the documented push-toggle guidance if you later want reminders turned off.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very broad phrases such as 'poetry', '诗词', and 'send me a poem', which can easily appear in ordinary conversation and cause unintended skill invocation. In a skill that can initiate recurring push behavior, accidental activation increases the risk of unsolicited actions and user confusion even though the skill is otherwise low sensitivity.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage section mixes one-time requests like '来首诗' with subscription-style behavior like '开启诗词推送' and automatic weekly sends, without a clear opt-in boundary. This ambiguity can lead the agent to interpret a casual poem request as consent for persistent notifications or scheduled tasks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.