Back to skill

Security audit

中文论文写作

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese academic writing and review assistant with optional, scoped source lookup and read-only audit scripts.

Install only if you are comfortable giving the agent the academic drafts and source materials you choose to provide. For sensitive theses or unpublished research, limit the files shared, decline local state files if you do not want continuity records, and authorize web/source searches only within a clear scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The skill is presented as a collaborative academic writing assistant, but the behavior described by the finding includes broader document-audit operations over multiple file types and cross-file consistency analysis. This mismatch is dangerous because users or reviewers may grant trust and sensitive academic materials under one expectation while the skill performs a materially different class of processing, increasing the risk of overcollection, unintended analysis, or policy bypass around what the skill is supposed to do.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.