Back to skill

Security audit

Vector Text Fixer

Security checks across malware telemetry and agentic risk

Overview

This is a local PDF/SVG text-repair helper with disclosed file access and no evidence of hidden network, credential, persistence, or destructive behavior.

Install dependencies deliberately, preferably pinned and from trusted package names. Run the tool only on copies of intended documents, review suggested fixes manually before relying on them, and treat JSON exports or logs as sensitive if the source documents contain private text.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
76% confidence
Finding
Aggressive repair and OCR-assisted recognition can silently alter document text content, which may introduce factual, legal, or operational errors into edited files. In a document-repair context this is especially relevant because users may trust the repaired output as authoritative, and the skill does not prominently warn that high-aggression repair can hallucinate or misrecognize text.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.