Back to skill

Security audit

博辩

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only Chinese text analysis helper with disclosed short comment generation and no code execution, credential use, network access, or persistence.

Install this if you want a Chinese-language helper for AI-writing-style analysis and concise stance comments. Treat its score as a style signal, not proof of authorship, and use any generated comments manually and responsibly rather than for harassment, political persuasion, or bulk/social account automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases include very generic requests such as “分析这篇文章” and “帮我从正反两面评论”, which can cause the agent to invoke this skill for ordinary article analysis or comment generation outside its stated niche of AI-writing-style analysis for Chinese blog posts. Over-broad activation can lead to misrouting, unintended policy application, and generation of persuasive comments in contexts the user did not intend, especially since the skill also supports support/oppose outputs.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.