编写企业客户培训大纲并生成DOCX文档

Security checks across malware telemetry and agentic risk

Overview

This skill is a document-writing helper that coherently creates corporate training outlines and DOCX files, with no evidence of hidden code, credential access, persistence, or unrelated behavior.

Before installing, understand that the skill may create a DOCX file and may fill in missing training details based on the topic. Confirm the intended output path, avoid providing confidential business secrets unless your agent environment is appropriate for that data, and review the generated document before sharing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to generate a DOCX and write it to a user-specified path or, by default, the working directory, without requiring explicit confirmation, path constraints, or disclosure of filesystem effects. This can lead to unintended file creation in sensitive or shared locations, overwrite/confusion risks, and makes the skill more dangerous because it performs a side effect beyond pure text generation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal