Back to skill

Security audit

TRPG Abbreviation Check (Rules)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed TRPG document editing helper, with no evidence of hidden execution, credential use, persistence, or exfiltration.

Before installing, treat this as an editing skill that may change many TRPG content files at once. Use it on a version-controlled project and review the proposed diff, especially if your project uses Simplified Chinese or mixed-language terminology.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to read all target files and then perform batch replacement and simultaneous write-back, but it does not require a user confirmation step or any warning that many files may be modified at once. In an agent setting, this increases the blast radius of mistakes from a single bad abbreviation mapping, incorrect file selection, or prompt-influenced misclassification into widespread unintended edits across rulebooks, scenarios, sheets, and reference files.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill states that Traditional and Simplified Chinese must match and that attribute names must use Traditional Chinese, effectively hard-coding a locale/output requirement without checking user preference or project conventions. This is less severe than direct code-execution or exfiltration issues, but it can still cause integrity problems by forcing unwanted script conversion, creating inconsistent terminology, and overwriting content in repositories that expect Simplified Chinese or mixed-locale assets.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.