loadpage

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only writing helper that openly edits text to sound less AI-generated, with no evidence of hidden code, exfiltration, persistence, or privileged behavior.

Install only if you want an agent to rewrite text for a more human style. Use it on documents you intend to edit, review changes before sharing, and avoid using it where rules require disclosure of AI assistance or where changing voice/authorship cues would be misleading.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description is broad enough to trigger on ordinary editing and review tasks, which can cause the skill to be selected outside narrowly scoped 'AI-writing cleanup' use cases. In this case, the risk is amplified because the skill explicitly aims to alter authorship cues and make text appear more human-written, so overbroad activation could lead to unintended ghostwriting or concealment of AI assistance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The task section reads like a general-purpose rewriting editor and lacks boundaries on when the skill should or should not be used. Because it instructs the model to 'add soul,' 'have opinions,' and use first person when appropriate, it can go beyond cleanup into substantive voice fabrication, increasing the chance of misleading authorship presentation or inappropriate use in sensitive writing contexts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill does not warn that its purpose is to remove signs of AI-generated writing and may materially alter voice, tone, and authorship cues. That omission matters here because the skill explicitly encourages injecting personality and changing stylistic markers, which could be used to disguise AI involvement or misrepresent who wrote the text.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal