Paper Summary

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple paper-summarization prompt with no executable code, persistence, credential access, or hidden behavior.

Install this if you want help summarizing academic papers. Be aware that broad summary requests may invoke it, and only provide PDFs, URLs, local paths, or pasted text that you are comfortable having your agent read and summarize.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises broad trigger phrases such as '文章总结' and '帮我理解这篇论文', which are common natural-language requests and can cause the skill to activate in situations beyond narrow academic-paper summarization. Overbroad activation increases the chance of unintended routing, where general document-analysis requests are handled by this skill and sensitive local files, URLs, or pasted content may be processed without clear user intent.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill is written to operate in Chinese throughout, with no indication that language should follow the user's preference. This can override user expectations, reduce transparency of consent and output review, and in security-sensitive contexts may cause users to misunderstand what content sources are being processed or what the summary actually says.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal