Back to skill

Security audit

Batch Processor Zh

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only bulk document processing skill; its broad activation and external tool dependency require care, but the artifacts show no hidden code, persistence, credential use, or exfiltration.

Install only if you intend to use a trusted office-mcp batch conversion tool. For sensitive HR, finance, legal, or procurement files, confirm the exact input folder, output folder, file types, and overwrite behavior before running a batch job, and keep backups for important documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description contains many broad, search-oriented trigger phrases covering generic office tasks, which can cause the skill to activate in situations beyond the user's actual intent. Over-broad activation increases the chance of inappropriate tool use on large file sets, especially for sensitive HR, finance, legal, or procurement documents mentioned in the skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.