Back to skill

Security audit

Diagram Maker

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk diagram-generation helper with disclosed SVG/HTML and Excalidraw outputs and no executable install or runtime behavior.

Install this if you want a Chinese-oriented helper for generating static diagram files. As with any generated HTML or JSON artifact, review outputs before sharing or importing them into other tools, but the inspected skill itself does not request sensitive access or ongoing privileges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
This markdown file describes activation through generic natural-language requests such as '画一个微服务架构图' and '画一个用户注册流程图'. Because the skill does not define a bounded trigger scope, negative examples, or contextual limits, these phrases overlap with ordinary conversation and could cause unintended invocation.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The natural-language content prominently presents the skill in Chinese and uses Chinese prompt examples, which can imply a default language expectation. There is no statement that users may interact in other languages or that the language choice is optional and justified.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.