Back to skill

Security audit

Article Tuwen

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed content-conversion workflow that creates local article/card outputs and only uploads generated files to Feishu after user confirmation.

Install only if you are comfortable with automatic web fetching/searching, external image downloads, sub-skill invocation, and Desktop file creation after you invoke it. Approve Feishu sync only when the generated article/cards are safe to upload, because generated outputs may still contain sensitive information derived from your source material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructions state that cover/back-cover images are downloaded from an external image source, which implies network activity and potential transmission of request metadata. While the line notes a 'data processing declaration,' this file does not actually present a concrete user warning about the network behavior or any privacy implications.

Missing User Warnings

Low
Confidence
73% confidence
Finding
These lines instruct the skill to append a run record and save rotation indexes to history.json, which persists user/workflow state on disk. The document does not clearly warn users that execution creates or updates a local history file retaining metadata across runs.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The entire skill file enforces Chinese-language instructions and user-facing phrasing such as the required confirmation prompt, but it does not indicate that the language is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.