Back to skill

Security audit

X Manual Surf Notes (手动刷帖笔记)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed X browsing and note-taking workflow, with privacy and local-file cautions but no evidence of hidden or malicious behavior.

Install only if you are comfortable letting the agent operate an attached logged-in X tab, read visible For You feed content, and append summaries to the specified markdown notes file. Review or change the output path before use, and avoid attaching the browser relay to unrelated sensitive pages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is broad and includes common phrases like '手动刷X' and 'X冲浪' without clear scoping or exclusion conditions, which can cause the skill to activate in contexts the user did not intend. Because this skill drives a browser and writes notes, accidental activation can lead to unintended browsing and data collection behavior rather than a harmless misfire.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill appends output to a hard-coded local file path without user-facing disclosure or consent at the point of use. This creates a risk of unintended local file modification, data leakage into an unexpected workspace, and persistence of collected content in a location the user may not realize is being changed.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The listing says the skill will append structured notes to a markdown file, but it does not clearly warn users in a safety/privacy-oriented way that local files will be modified. Even if the write target is expected behavior, undisclosed file writes can surprise users, lead to accidental data mixing, and cause minor integrity or privacy issues if notes are stored in a sensitive location.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill description states that it controls an existing Chrome tab and reads content from the user's X feed, but it does not prominently warn about the privacy implications of browser control and feed access. Because this involves interacting with a live authenticated browsing session, the skill could expose personal timeline data, recommendations, account context, and adjacent page content beyond what users may expect from a simple summarization workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.