Back to skill

Security audit

copyku

Security checks across malware telemetry and agentic risk

Overview

This is a plain copywriting helper skill with no executable code, hidden data access, persistence, or privileged actions.

Before installing, understand that this skill is designed to produce persuasive marketing copy. Review outputs carefully before publishing, especially for health, finance-adjacent, property, legal, or regulated advertising claims, and provide accurate compliance notes where relevant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The markdown advertises industry templates including Health and Property, with examples like clinical claims and doctor recommendations, but does not warn users to verify legal, medical, or advertising compliance before use. Because this file is the skill description, omission of a warning about potentially high-impact persuasive content affecting user trust or regulated claims fits the markdown-file warning criterion.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The README is predominantly written in Indonesian and presents Indonesian as the default workflow language, while other languages appear as optional modes later. This can be read as a locale/language preference being imposed by default rather than explicitly offering the user a language choice upfront.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill says users can 'langsung sebutkan' phrases like 'caption produk skincare', 'headline kursus online', and 'iklan makanan ringan' to invoke it. These are generic everyday content requests, and the document does not provide exclusion conditions or clear boundaries for when the skill should or should not activate, increasing the risk of unintended invocation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The 'Smart Detection' section maps very common words like 'caption', 'headline', 'story', 'bulk', and 'seo' to automatic behavior changes. These keywords overlap with normal conversation and editing requests, and the file does not document constraints or non-trigger cases, making the trigger scope overly broad.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.