Back to skill

Security audit

对话生产器(自用)

Security checks across malware telemetry and agentic risk

Overview

This skill locally creates synthetic group-chat Excel files and does not show hidden data access, credential use, exfiltration, or destructive behavior.

Install only if you are comfortable running local Node.js scripts and installing the xlsx npm dependency. Treat generated chat logs as synthetic data, avoid impersonating real people without permission, and choose explicit input/output paths so important files are not overwritten.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal