Back to skill

Security audit

humanizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed text-editing helper that rewrites user-provided text, with some metadata and fallback-language issues users should notice before using it.

Install only if you want an agent to rewrite text to sound less AI-generated. Use it on explicit requests and review changes before applying them, especially for academic, legal, compliance, archival, or authorship-sensitive documents. Be aware that language fallback behavior is poorly specified and may need correction by the user.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README says the skill can be invoked directly when editing documents, which is broad enough that an agent may apply the transformation automatically in many contexts. Because the skill rewrites text to remove signs of AI generation, ambiguous triggering can cause unintended modification of user content, authorship signals, policy text, or records where preserving original wording matters.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill defines a fallback policy that defaults to processing in Chinese when language detection fails, without asking the user or preserving the original language. That can cause unintended language switching, garble output, or produce content the user cannot verify, which is especially risky in an editing skill where fidelity to user intent matters.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description is effectively content-free ('|') and does not meaningfully describe the skill's purpose or activation conditions. This can hinder review, obscure the skill's real behavior, and make it easier for unsafe or misleading functionality to evade scrutiny, though the package.json shown does not by itself demonstrate active malicious behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.