Back to skill

Security audit

Batch Convert Zh

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only batch document conversion skill with ordinary batch file handling risks, but no evidence of hidden, destructive, credential-seeking, or unrelated behavior.

Before using it, confirm the external converter is trusted, choose narrow input folders, set a separate output directory, and back up important documents or confirm overwrite behavior before running large batches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match ordinary document-assistance requests, which can cause the skill to activate in situations where the user did not clearly intend bulk file conversion. In a file-processing skill, ambiguous activation increases the chance of unintended batch operations over user-selected directories and can lead to unnecessary file creation or conversion actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes batch conversion workflows but does not warn that running the tool may create many output files or overwrite existing files in user-specified locations. For batch operations, this omission is risky because a mistaken path or unchecked overwrite behavior can cause large-scale data loss, clutter, or modification of important working directories.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.