Back to skill

Security audit

公众号文章排版

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent article-formatting helper that creates local WeChat or Toutiao HTML layouts without hidden network, credential, or privileged behavior.

Install if you want help producing WeChat or Toutiao article HTML. Use clear platform wording, review the generated HTML before publishing, and check the output filename/path when working in a directory that may already contain generated article files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough that the skill may activate on loosely related requests such as generic article creation or formatting, not just explicit requests for this specific output. Over-broad invocation increases the chance the agent applies this skill unexpectedly, causing incorrect behavior, policy bypass of better-matched skills, or generation of HTML output when the user did not intend it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.