title
Security checks across malware telemetry and agentic risk
Overview
The skill's files, requirements, and runtime instructions are internally consistent with its stated purpose (title generation for Xiaohongshu); no credentials, installers, or external network operations are requested, though there are small implementation/documentation inconsistencies and subjective filtering rules to review before use.
This skill appears coherent and low-risk from a security perspective (no network installs or secret access). Before installing, review two small issues: (1) the SKILL.md text refers to a validate() function and a '200+ examples' library whereas the included validator is named validate_titles and the examples file is small — confirm the bundled files match the documented behavior; (2) the workflow relies on a vague subjective filter ('feels AI-generated') — decide whether you trust the agent's judgment or want a stricter, auditable filter. Also consider the ethical/brand risk: the strategy explicitly encourages emotional hooks and urgency words which may conflict with platform policies or ad laws — ensure generated titles comply with local advertising rules. If you want extra caution, run the skill in a sandbox, inspect examples.md completely, and test the validator's outputs before using titles publicly.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
