Back to skill

Security audit

md2wechat

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent wrapper for the md2wechat publishing CLI and includes clear safeguards around uploads, drafts, credentials, and file writes.

Install this if you intend to use the md2wechat CLI for WeChat article formatting or publishing. Review your local md2wechat configuration first, and only approve upload, draft, publishing, or image-generation actions when you are comfortable with the relevant account or provider credentials being used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description uses very broad activation criteria such as formatting, preview, draft upload, image generation, title suggestions, AI-trace removal, and discovery of supported providers/themes/prompts. This can cause the agent to invoke the skill for many ordinary content tasks, increasing the chance of unintended command execution, exposure to side effects, or routing user requests into a high-capability tool without sufficiently specific user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.