Back to skill

Security audit

libai-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese text rewriter, but its core workflow is designed to hide AI authorship and can be used to mislead reviewers.

Install only if you want an explicit, user-controlled Chinese rewriting tool and you will not use it to hide AI authorship where disclosure, academic integrity, editorial policy, or professional review matters. Prefer diagnostic-only mode or ordinary clarity editing for sensitive work, and review any added personal details because the workflow can inject human-sounding cues not present in the source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The quickstart advertises very broad, natural-language trigger phrases such as '文章润色', '文本润色', and '帮我改一下', which can overlap with ordinary user requests and cause the skill to activate when the user did not explicitly intend to invoke this specific behavior. In a skill designed to rewrite text to reduce detectable AI traits, unintended activation increases the chance of unexpected content transformation, policy bypass attempts, or silent alteration of sensitive academic/professional material.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is broad and includes generic terms like “润色” and “改写,” which are common in ordinary writing requests. This increases the chance of unintended skill activation, causing the agent to apply de-AI rewriting behavior when the user did not explicitly request this specialized transformation.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad, short, everyday phrases such as '人味' and generic rewriting terms, which can cause accidental invocation in unrelated conversations. Unintended activation matters here because the skill is designed to rewrite text to remove AI-detection cues, so firing unexpectedly could alter user content in deceptive or policy-sensitive ways.

Ssd 2

Medium
Confidence
93% confidence
Finding
The skill's stated purpose is to detect and remove 'AI traces' so output passes human review, which directly facilitates concealment of AI authorship. This is dangerous because it can be used to evade disclosure requirements, editorial review policies, academic integrity controls, or trust-and-safety systems that depend on transparent provenance.

Ssd 2

Medium
Confidence
94% confidence
Finding
The trigger phrases and workflow are explicitly built around 'de-AI' and 'humanize' terminology, making concealment of machine authorship a first-class feature rather than an incidental effect. In context, this increases the risk of routine misuse for ghostwriting, policy evasion, and fraudulent submission of AI-generated work as human-authored content.

Ssd 4

Medium
Confidence
95% confidence
Finding
The multi-step instructions provide systematic guidance for making AI-generated text appear human, including deleting telltale patterns, injecting personal details, and ending in ways that avoid detection heuristics. This goes beyond normal editing assistance and operationalizes deceptive transformation, making it easier for users to circumvent review processes or misrepresent authorship at scale.

Ssd 4

High
Confidence
93% confidence
Finding
The class documentation explicitly maps the pipeline to removing AI-generation signals and converting text to pass human review. In the context of a rewriting skill, this is dangerous because it operationalizes deception-by-transformation and can be used to evade provenance, moderation, or policy checks rather than merely improve style.

Ssd 2

High
Confidence
96% confidence
Finding
The rewrite stages are explicitly labeled as deleting 'AI traces,' removing chatbot artifacts, searching for 'black words,' and restructuring output to appear more human. In this skill's context, that is not neutral paraphrasing; it is a deliberate anti-detection workflow that can help launder synthetic, suspicious, or policy-sensitive text.

Ssd 4

High
Confidence
97% confidence
Finding
This block increases rewrite aggressiveness when the input matches high-risk patterns, tier1 circuit-breaker signals, or banned-word indicators. That escalation logic makes the system more dangerous because it adapts specifically to suspicious input and intensifies transformations precisely when content is most likely to need containment, not concealment.

Ssd 4

Medium
Confidence
90% confidence
Finding
The second tier uses the same risk signals to enable stronger structural rewriting via sentence splitting, further obscuring recognizable patterns. Combined with the skill's stated purpose of removing AI traces and improving passage through human review, this acts as an additional evasion layer rather than a harmless readability feature.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
84% confidence
Finding
The trigger '人味' is unusually short and semantically broad, so it is likely to match benign discussion rather than deliberate skill invocation. In a skill that performs substantial rewriting and anti-detection-oriented transformation, that ambiguity raises the chance of accidental or contextually inappropriate activation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.