Briefing-pro

Security checks across malware telemetry and agentic risk

Overview

This skill coherently turns user-provided text, URLs, or files into one-page briefing slides, with expected document parsing and webpage fetching disclosed.

Install if you want a briefing generator that may fetch supplied URLs and read uploaded files to create slide-style output. Avoid using it for sensitive documents unless you are comfortable with that content being parsed and rendered, and consider narrowing the generic “摘要” trigger to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions include very broad everyday terms such as “摘要”, which can match many unrelated user requests and cause unintended activation of this skill. Because the skill fetches URLs, parses uploaded files, and generates outputs automatically, accidental invocation could expose user content to unnecessary processing or lead the agent down the wrong workflow.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal