Back to skill

Security audit

超能去AI

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese creative-rewriting skill with no executable code or hidden access, but it may add invented details and should not be used for factual or sensitive documents.

Install only if you want Chinese creative, informal, or marketing-style text rewritten with a more human voice and you accept that the skill may restructure text or add color. Do not use it for academic work, contracts, legal or medical text, news, evidence, technical documentation, business reports, citations, or anything where exact facts, numbers, provenance, and structure must be preserved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill claims it will preserve facts, names, times, and citations, but simultaneously requires replacing precise numbers with subjective descriptions and adding details not present in the source. That contradiction can cause silent distortion of user content while presenting the output as faithful rewriting, which is especially risky when users apply it to informational or mixed-factual text.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill says factual documents should be left unchanged, yet its routing logic still matches business analysis, technical writing, workplace reports, and science explainer content into rewrite roles. This inconsistency makes accidental misuse likely, because the model may proceed with transformation on content classes the skill itself says are unsafe for alteration.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The skill is framed as 'de-AI rewriting,' but it mandates adding misleading narrative devices such as false leads, unresolved details, and required protagonist mistakes. These changes go beyond style transfer and deliberately alter semantic content, which can normalize fabrication under the guise of humanization.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains broad, conversational phrases such as '帮我改一下' and '太像AI了帮我改改' that could plausibly appear in ordinary user text, increasing the chance of accidental skill activation. In a rewriting skill that intentionally alters content style and may add details, unintended invocation can cause unauthorized transformation of user content or unexpected behavior in unrelated workflows.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill description and role content explicitly state that it is designed specifically for Chinese text, but there is no indication that the user can choose another language or opt in to this restriction. This can cause unintended exclusion, user confusion, or mishandling of multilingual requests, especially if invoked in contexts where language preference should be respected.

Ssd 4

High
Confidence
98% confidence
Finding
This section instructs the model to incrementally insert fabricated narrative signals—irrelevant details, gray morality, memory anchors, false suspicions, and other realism cues—while preserving the appearance of a benign rewrite. That is dangerous because it systematizes deceptive content generation in a way that can mislead readers about what originated in the source versus what was invented by the model.

Ssd 4

High
Confidence
98% confidence
Finding
The hard constraints make deceptive augmentation mandatory by requiring added irrelevant objects, dead-end clues, trauma-linked sensory details, and other invented elements. Because these are framed as non-optional constraints, the skill strongly pushes the model toward fabricated output even when the user may expect faithful rewriting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.