Back to skill

Security audit

S.H.I.T Journal 论文推荐

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for recommending parody papers from a disclosed website, with broad trigger phrases as the main caveat.

Install only if you are comfortable with the agent visiting shitjournal.org for parody academic content. Be aware that broad phrases like “random paper” may invoke it unexpectedly; prefer explicit requests naming S.H.I.T Journal or the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description embeds broad trigger phrases such as '随机论文' that can overlap with ordinary user requests unrelated to this specific parody journal. In an agent environment, this can cause unintended skill activation and tool use against an external website, creating prompt-routing confusion and surprising behavior rather than a direct code-execution flaw.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger section contains ambiguous activations like '随机论文' and '搞笑学术' without boundaries, which are likely to match many normal requests. Because the skill is designed to browse a third-party site and return content, accidental invocation could lead to irrelevant web access, poor user intent matching, and possible exposure to adult or unexpected content from the target site.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.