SRT Proofreader

Security checks across malware telemetry and agentic risk

Overview

This skill performs local subtitle proofreading with disclosed file edits and no evidence of hidden network, credential, or destructive behavior beyond its stated editing workflow.

Use this skill in a dedicated srts/ folder, keep unrelated or sensitive files out of that folder before git add . runs, and review the final git diff before accepting the subtitle changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly instructs the agent to overwrite the main .srt after splitting and merging, but the skill description does not clearly warn that it will modify tracked files in place. In an agent setting, hidden write/overwrite behavior can cause unintended data loss or user surprise, especially when the merge step replaces the original subtitle file.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal