Back to skill

Security audit

超能去AI

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese text-rewriting skill with disclosed creative embellishment behavior and no executable, network, credential, or hidden background behavior.

Install only if you want a Chinese creative or informal rewriting tool. Do not use it for legal, academic, news, technical reference, financial, compliance, or other fact-sensitive documents unless you manually verify every preserved fact and number afterward.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill explicitly requires adding invented elements such as私人细节、闲笔、干扰项、人性灰度 and structural changes while also claiming not to change facts or core meaning. This creates a high risk of fabricated content being introduced into user material, especially when users may apply it to borderline factual or mixed-content texts.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill says factual texts are not applicable, but its routing logic still matches technical, business, workplace, and science content to rewrite roles. That means users can easily be funneled into transformation workflows for texts where precision matters, increasing the chance of distortion, invented nuance, or loss of factual fidelity.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The hard constraints claim facts must not change, yet the same section mandates replacing exact numbers with subjective impressions and adding new narrative content such as irrelevant objects, misleading clues, and personalized memory links. These directives are directly incompatible and can cause silent corruption of factual detail or evidence-bearing text.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains common conversational Chinese phrases such as '去AI痕迹' and '帮我改一下,太像AI写的了', which are broad enough to appear in ordinary discussion rather than an intentional request to invoke the skill. This can cause accidental activation and unintended processing of user content, especially in multi-skill environments where trigger matching is automatic or fuzzy.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file defines a Chinese-only persona and writing style without any user language selection or fallback behavior. This can override user expectations, reduce transparency, and cause the agent to respond in an unintended language or persona, which is especially problematic in multilingual or accessibility-sensitive contexts.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This role file is explicitly written only for Chinese-language rewriting and does not provide any mechanism to preserve the user's original language or request consent before switching style/language expectations. In practice, that can cause unwanted language coercion, loss of user control, and incorrect handling of multilingual or non-Chinese inputs, though it is not a classic security exploit.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.