创建微信视频号合集_无限

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed instruction-only skill for creating a WeChat Channels collection in a logged-in browser session, with no hidden code or unrelated data access.

Install only if you want an agent to operate a logged-in WeChat Channels backend session. Before allowing creation, confirm the correct account, exact collection title, and intended action, especially because one trigger phrase is broad enough to match non-WeChat requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are generic action phrases like '创建视频号合集' and '创建视频合集' without clear scoping, confirmation, or contextual boundaries. This can cause the skill to activate on ambiguous user requests and perform real actions in a sensitive publisher backend, increasing the chance of unintended content-management changes.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal