Back to skill

Security audit

TRPG Convert to Briefing Package

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed TRPG document-conversion helper that edits local game package files and does not show hidden, destructive, credential, network, or persistence behavior.

Install only if you want converted package content normalized to Traditional Chinese and Chinese-full-name-plus-abbreviation terminology. Use it in a dedicated TRPG project folder because it is designed to inspect and edit multiple active local rule and scenario files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill hard-codes Traditional Chinese for all Chinese output and requires Chinese full names alongside English abbreviations, removing user choice over language/script. This is not a code-execution or data-exfiltration issue, but it is a real policy/UX constraint that can cause unauthorized transformation of user-provided Simplified Chinese text and reduce interoperability when the user or surrounding workflow expects another language form.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.