Back to skill

Security audit

Write Literature Review

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent literature-review writing assistant with no executable code, persistence, credential handling, or hidden high-impact behavior.

Installers should expect the skill to read the academic files they provide and to optionally use external literature only if they permit it. It is best suited for users comfortable with Chinese-language skill instructions, though the requested review output can be Chinese or English.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file content is entirely in Chinese and presents the review-writing structure as a default, which can effectively force a language choice without any visible user opt-in or locale-selection logic. In an agent skill, this can cause the system to ignore user language preferences, reduce usability, and produce outputs in an unintended language, especially for multilingual or English-speaking users.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.