Back to skill

Security audit

TCMS Adapter

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed marketing-content adapter that reads approved drafts or published articles and writes channel-specific copy, with no hidden execution or unrelated data handling found.

Install this if you want a TCMS-family workflow for adapting already-reviewed marketing drafts or published articles. Confirm the source content has passed review and choose target channels deliberately, especially because generic rewrite requests could otherwise activate this skill and the X output is intentionally English.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes short, generic terms such as "adapt" and "repurpose" that can plausibly appear in many unrelated requests. In an agent system that auto-selects skills by trigger phrases, this can cause unintended invocation, routing user content into a brand-marketing transformation workflow when a different skill or no skill should have been used.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes broad, everyday terms such as '适配', '改写', and 'adapt', which can match many unrelated user requests and cause the skill to activate outside its intended workflow. In this skill's context, accidental invocation matters because the adapter is only supposed to operate on already-reviewed brand content; misfires could bypass that precondition and lead to inappropriate channel-specific generation from unreviewed inputs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README states the skill should only adapt already-reviewed core drafts, but the trigger section does not encode that prerequisite and instead lists generic rewrite/repurpose terms. This mismatch can cause the skill routing layer or users to treat it as a general-purpose rewriting tool, increasing the chance that compliance, redaction, and brand-consistency checks expected earlier in the pipeline are skipped.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation terms are broad generic rewrite/adaptation keywords in both Chinese and English, with no requirement that the request be product-marketing content or that an approved core draft already exists. This can cause the skill to trigger on unrelated rewriting tasks, leading to misuse outside its intended reviewed-content workflow and bypassing more appropriate safeguards or approval-oriented skills.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill hardcodes English output for X posts and says English-thinking writing rather than translation, but does not require the user to request English or confirm that English output is desired. In practice this can produce content in an unintended language, creating user-intent mismatch, publication errors, or accidental policy bypass where language choice should remain user-controlled.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.