Voice Note Polisher

Security checks across malware telemetry and agentic risk

Overview

This is a text-only skill for cleaning up dictated or informal notes, with no code execution or access to private systems, but it may activate too broadly for some users.

Install this if you want automatic cleanup of dictated or informal text. Review outputs before sending emails, public posts, or multilingual content, and be aware that broad Chinese trigger phrases may cause the skill to rewrite text when you only intended a general edit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill is configured to trigger on broadly defined 'oral' or colloquial text, even when the user does not explicitly indicate they want this skill. In an agentic routing system, this can cause unintended invocation on ordinary messages, rewriting user content into a different format without clear consent and potentially interfering with task selection or downstream safety controls.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Using a very generic phrase like '帮我整理一下' as a trigger creates overlap with common conversation, making accidental activation likely. While this is not directly code-execution dangerous, it can misroute benign user input, cause unwanted rewriting, and reduce reliability of the broader assistant behavior.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal