Back to skill

Security audit

Journal to Post

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward writing skill for turning selected journal entries into social posts, but users should review private details before sharing.

Install only if you want a writing aid for journal content you intentionally choose to turn into public posts. Do not provide secrets, confidential work material, health or financial details, or unreviewed files, and manually remove identifying details before posting any generated text.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill advertises broad handling of 'journal text or file path' and is framed generally enough that an agent could invoke it for many journaling- or reflection-related requests without clearly signaling that the output is intended for public sharing. In this context, overbroad triggering increases the chance that private or sensitive personal content is transformed into a social-media-ready form when the user did not intend publication, creating a privacy and consent risk.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill lacks a prominent warning that personal journal content may be converted into shareable public posts, even though journal entries commonly contain intimate, identifying, or otherwise sensitive information. Because the skill encourages users not to self-censor and says it will 'filter for you,' users may overtrust the transformation process and inadvertently expose private details, emotional disclosures, health information, work incidents, or other sensitive data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.