Back to skill

Security audit

Zhihu Publisher

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it can publish publicly to a user's Zhihu account without a required final confirmation step.

Install only if you are comfortable letting an agent control a logged-in Chrome session for Zhihu. Before use, require the agent to show the final article title/content and ask for explicit approval before clicking publish; provide credentials interactively and do not store them in files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill performs a real external publish action to Zhihu and defines a direct click path for the final publish button without requiring an explicit user confirmation immediately before submission. In an agentic environment, this increases the risk of unintended posting, accidental publication of drafts, or submission of sensitive or unreviewed content under the user's account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.