Back to skill

Security audit

gongwen_format

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese official-document writing helper with disclosed scope; the main risk is overly broad activation, not hidden or unsafe behavior.

Install it only if you want help with Chinese official or formal work documents. Invoke it explicitly for those tasks, review any official/legal/financial/policy-sensitive output manually, and only run the included linter on draft files you intend the agent to inspect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes short and generic phrases such as 'create official document', '公文格式', '发文', and '工作报告' that can overlap with ordinary writing or business requests. In an agent-routing context, overly broad triggers can cause unintended activation of this skill, leading to misrouting, incorrect formatting assumptions, or suppression of a more appropriate skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.