Back to skill

Security audit

ai-conversation-optimizer

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-improvement helper with no executable code, credential access, persistence, or hidden system behavior.

This skill appears safe to install for Chinese-language prompt coaching. Be aware it may activate on broad questions about AI answer quality, and avoid pasting secrets or private data into prompts unless you intend the assistant to process that content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are very broad, generic user requests such as asking why an AI answer was wrong or how to ask better questions. In an agentic skill-routing system, this can cause over-triggering, where the skill activates in ordinary conversations and may intercept requests not intended for this specialized workflow, reducing reliability and potentially influencing downstream behavior unexpectedly.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill metadata and output template are Chinese-specific and do not offer language negotiation or user-choice. While not directly a security flaw, this can create unsafe operational behavior in multilingual environments by causing unintended output-language coercion, misrouting, or user confusion that degrades transparency and correct use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.