Back to skill

Security audit

公众号写手

Security checks across malware telemetry and agentic risk

Overview

This is a writing-assistant skill with no executable or network behavior, but it does ask to maintain a local usage log and occasionally edit its own skill file.

Before installing, decide whether you want the skill to write usage notes and revise its own SKILL.md over time. For normal article drafting this appears safe, but you should require explicit approval before it edits EXPERIENCE_LOG.md or SKILL.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill is granted Write and Edit permissions and explicitly instructs the agent to record usage outcomes into EXPERIENCE_LOG.md and periodically update SKILL.md. Without a clear user-warning or consent boundary, the agent could modify local files as a side effect of ordinary writing requests, creating unauthorized workspace changes and potential prompt-surface contamination for future runs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.