Text Repeater

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only text utility for repetition and Unicode formatting, with disclosed but misuse-adjacent invisible-character features.

Install this only if you want a text repetition and Unicode formatting helper. Be careful with invisible or blank characters: inspect copied output before pasting it elsewhere, and do not use blank names or invisible messages to impersonate people, evade moderation, or confuse readers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger guidance is broad enough to match many generic text-formatting or pasted-text requests, which can cause the skill to activate when the user did not specifically want repetition or transformation behavior. Over-broad invocation increases the chance of inappropriate tool selection, unexpected handling of user content, and misuse of adjacent features such as invisible-character generation.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs the agent to write user-supplied content to a file in /mnt/user-data/outputs without clearly warning the user that their text will be persisted to disk. That creates a privacy and data-handling risk, especially if users provide sensitive text expecting only ephemeral in-chat transformation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal