Windows Printing

Security checks across malware telemetry and agentic risk

Overview

This Windows printing skill has a legitimate purpose, but it tells the agent to run missing PowerShell helper scripts before performing real print actions.

Review before installing. The skill’s printing purpose is clear, but do not rely on it unless the publisher provides the missing PowerShell scripts or a corrected package. Before any print job, confirm the file, printer, copies, color mode, duplex mode, and paper size, and check printer settings afterward on shared or important printers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description uses broad trigger terms like “打印”, “打印机”, and common document/media references, which can cause the skill to activate for loosely related user requests. In this context, unintended invocation is meaningful because the skill can enumerate local files and printers and eventually perform a real-world side effect: sending a document to print.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal