Back to skill

Security audit

TRPG Write Public Introduction

Security checks across malware telemetry and agentic risk

Overview

This skill coherently helps generate and save a public TRPG introduction, with only limited local file access and one disclosed output file.

Install this for TRPG projects where you want an agent to read the rule materials and draft a public introduction. Before use, confirm the intended rule directory and check whether a [rule name]_介紹.txt file already exists if preserving prior text matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs the agent to write a new file into the workspace automatically, without requiring an explicit user confirmation at execution time. This can cause unintended filesystem modifications, overwrite similarly named content, or create persistence side effects that the user did not knowingly authorize.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.