中文文本校验

Security checks across malware telemetry and agentic risk

Overview

This appears to be a proofreading helper with broad trigger words, but there is no artifact-backed evidence of hidden access, persistence, credential use, or destructive behavior.

Install this if you want a proofreading/document-checking assistant, but be aware that common trigger words may activate it more often than expected. Review what document content you provide to it, especially if the text contains confidential material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords include broad, everyday terms such as '校对', '检查文档', and 'proofreading', which can cause the skill to be invoked in situations the user did not specifically intend. In an agent environment, overly broad routing increases the chance of incorrect tool selection, unintended file access prompts, or processing of unrelated content.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal