Back to skill

Security audit

gov-report-writing

Security checks across malware telemetry and agentic risk

Overview

This is a document-writing skill with disclosed local file handling and formatting guidance, but its activation wording is broad enough that users should invoke it deliberately.

Install only if you want a specialized Chinese formal-document drafting workflow. Avoid giving it classified, confidential, or sensitive internal material; use placeholders or sanitized excerpts and review generated facts, names, dates, and policy references before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README uses broad natural-language trigger examples such as '帮我写…' and '按公文格式…', which can overlap with ordinary writing requests that are not necessarily intended for this specialized skill. In an agentic environment, that increases the chance of accidental invocation, causing the skill to process user content in an unintended workflow and potentially apply domain-specific behavior or document handling rules without clear user opt-in.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword table includes short, ambiguous terms like '总结', '方案', '会议', and '汇报' without scope restrictions. These keywords are common in ordinary office and personal requests, so a routing system may over-match and invoke this skill outside its intended regulated-document context, leading to misclassification of user intent and unnecessary exposure of content to this skill's processing path.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match many ordinary writing requests, which can cause the skill to activate outside its intended government-document context. Over-broad activation increases the chance of inappropriate instruction injection into unrelated conversations, unexpected file handling, or generation of authoritative-looking bureaucratic content when the user did not ask for this specialized workflow.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest describes many situations that should trigger the skill but does not clearly define when it must not activate. Without explicit exclusion boundaries, a router may invoke this skill for ambiguous requests, increasing the risk of cross-skill interference, accidental processing of sensitive workplace text, and misuse of public-sector writing conventions in contexts where they are not appropriate.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill unconditionally limits output to Chinese official-document writing and rejects English-version requests rather than checking user preference or offering a safe fallback. While not a direct code-execution issue, forced single-language behavior can cause denial of expected functionality, misrouting, and poor user control, especially if the skill activates on multilingual or translation-adjacent requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.