Back to skill

Security audit

Repo

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent WeChat cover generator that reads article/image inputs, calls image generation, and writes cover files as expected for its purpose.

Install this when you want an agent to read an article or topic, use image-generation credits, and create cover image files in the article or selected output folder. Use a dedicated output directory or check existing filenames first if overwriting previous cover assets would matter.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation phrases are broad enough to overlap with ordinary design or image-editing requests, which can cause the skill to trigger when the user did not explicitly intend to invoke it. In an agent setting, unclear invocation scope can lead to unintended processing of attached articles or unnecessary calls to image-generation and local post-processing steps, creating avoidable privacy, cost, and workflow-integrity risks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad phrases such as '封面图' and '文章配图' that can match many ordinary image-design requests, increasing the chance this skill activates when the user did not specifically want the WeChat cover workflow. In an agent environment, misrouting can cause unintended file access or image generation actions under the wrong skill.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill states that output is written automatically to the article's directory, but it does not mention prompting the user, naming conventions, overwrite behavior, or where files will be placed. In a filesystem-enabled agent, silent writes can overwrite existing assets, leak information about directory structure, or create unexpected files in sensitive workspaces.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.