Back to skill

Security audit

Drawing Cleaner

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Markdown drawing-text cleanup tool with disclosed file reading and output writing.

Install it only if you want a local drawing-text Markdown cleanup helper. When using it, specify the intended input and output files, run it in a directory without unrelated Markdown files, and review any proposed changes to its cleaning rules before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases like '清洗图纸文本', '去掉噪声', and '整理提取结果' are broad enough to match ordinary editing or summarization requests, increasing the chance the skill is invoked when the user did not intend file-processing behavior. Because this skill can read input files and write cleaned outputs, overbroad triggering raises the risk of unintended execution and data handling in the wrong context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.