Back to skill

Security audit

Emergence Blog Writing

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only blog-writing skill with some disclosed file-writing and promotional-link behavior, but no evidence of hidden execution, credential access, exfiltration, or destructive actions.

Install only if you want an agent to help draft and structure public-facing blog content. Before use, tell the agent whether it may create files such as idea.md, avoid giving it private logs or interviews unless you want them used in drafts, and review generated first-person claims, links, and calls to action before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The usage guidance tells users to add the skill to an agent and invoke it with broad categories of input material, but it does not define clear trigger conditions, scope boundaries, or prohibited contexts. In an agent ecosystem, ambiguous invocation rules can cause the skill to activate on unintended tasks or sensitive inputs, increasing the chance of prompt-scope bleed, misuse, or unsafe autonomous behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to persist user-derived refinements to a local file (`idea.md`) via `scaffold.sh` without requiring user consent, preview, or disclosure. Silent file writes can create unintended data retention, overwrite project state, or store sensitive brainstorming content in the workspace, which is especially risky in an agent environment that may have filesystem access.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill mandates first-person phrasing using Chinese forms like “我/我们” as a default persona rather than adapting to the user's language and attribution preferences. While not a severe security issue, this can misrepresent authorship, create deceptive self-claims such as 'personally tested,' and cause the agent to present unverifiable first-person experience without user approval.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.