Back to skill

Security audit

Literary Essay Writer 1

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese literary writing helper that only provides writing guidance and does not run code, access data, or request permissions.

Safe to install from a security perspective. Use it intentionally for Chinese literary essays, deep book reviews, and reflective public-account style writing; it may steer broader writing prompts toward that voice if your agent routes to it automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description includes broad trigger scenarios such as writing book reviews, reflections, and humanistic interpretations, which can overlap with many generic writing requests. In an agentic routing system, this can cause the skill to be invoked outside its intended niche, leading to prompt hijacking of normal writing tasks, instruction shadowing, or unintended influence over outputs.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill is written entirely in Chinese without stating a locale restriction or language-selection behavior. In multilingual environments, this can cause misrouting, user confusion, or silent instruction mismatch if the system applies the skill to users who did not request Chinese output.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.