mar-content-writer

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese social media writing helper with no install scripts, credentials, file access, or system-level behavior.

Before installing, understand that this skill may activate on broad writing prompts, so use it when you specifically want Chinese social media content and review outputs before publishing. Do not assume the referenced seo-optimizer exists or grant any extra tool/account access unless separately reviewed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation phrases are broad enough to match many ordinary writing-related requests, which can cause the skill to trigger outside its intended scope. In an agent environment, overly permissive activation can lead to inappropriate tool/skill selection, unexpected content generation, and reduced user control over which behavior is invoked.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal