Security audit
OriginWriter - 百万字小说写作引擎
Security checks across malware telemetry and agentic risk
Overview
This skill is a local novel-writing workflow that stores story state and runs explicit Node commands, with no hidden data access or unrelated behavior evident.
Before installing, confirm the real repository behind the placeholder is the one you intend to trust, then run the self-test first. Expect the tool to read and write the novel spec/package files you point it at, because that persistence is its core function.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
62/62 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
