Back to skill

Security audit

TRPG Abbreviation Wrap

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped TRPG document cleanup guide that edits local text and spreadsheet files only when the user asks for Chinese abbreviation normalization.

Install only if you want an agent to normalize TRPG abbreviation terminology in Chinese project documents. Confirm the target files and abbreviation mapping before running it, especially because it may edit .md, .txt, and .xlsx content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill description hardcodes Chinese-output formatting and does not indicate any user language preference, opt-in, or fallback behavior. This can cause unintended transformation of user content into a specific language convention, which is a prompt-safety and user-intent alignment issue even though it is not directly a code-execution or data-exfiltration risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.