Back to skill

Security audit

Thesis Title Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed academic writing helper for generating Chinese-English thesis title options, with no executable code or hidden system access.

Install this if you want bilingual Chinese-English thesis title suggestions. Be mindful that using it may involve pasting thesis drafts, abstracts, or findings into your agent, so avoid sharing confidential academic material unless you are comfortable with that workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is written with very broad trigger language such as refine, rename, translate, compare, or generate title recommendations from many kinds of academic content. That can cause over-selection for generic writing or translation requests and route users into a narrowly scoped skill that expects full thesis content, increasing the chance of unnecessary disclosure of sensitive academic material or poor task routing.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill defaults to bilingual Chinese-English output without making user language preference an explicit prerequisite. In practice, this can cause unnecessary transformation of user-provided academic content into another language, which may expose more information than needed and produce outputs the user did not request, especially in multilingual or privacy-sensitive academic workflows.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The guide hard-codes bilingual Chinese-English output as the default behavior without first checking the user's language preference. This can cause unwanted translation, unnecessary disclosure or transformation of user-provided academic content, and misalignment with user intent, though it is primarily a product-scope and consent issue rather than a direct security exploit.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The required output template forces both Chinese and English titles by default, removing user choice over language and output minimization. In a skill that processes full thesis drafts, this increases the chance of unnecessary transformation or exposure of sensitive academic material into another language, even if the overall risk remains limited.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The revision checklist enforces a rule that every response must include both Chinese and English titles, which institutionalizes the lack of language opt-in across the skill. This makes the behavior persistent and harder for higher-level safeguards to override, creating a repeatable privacy and user-intent mismatch issue rather than a severe security flaw.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.