Back to skill

Security audit

Dandan Humanize Text

Security checks across malware telemetry and agentic risk

Overview

This skill is instruction-only, but its stated purpose is to help AI-written text evade detection tools and it includes under-disclosed third-party text submission examples.

Review carefully before installing. Use only for transparent editing and readability work, not to bypass school, workplace, publisher, or platform AI-disclosure rules. Do not send confidential, proprietary, unpublished, or personal text to the GPTZero examples unless you intentionally accept that third-party disclosure, and do not run the referenced helper scripts unless you inspect and trust them separately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough to activate on common user phrasing such as requests to make text 'more natural' or '去 AI 味', increasing the chance the skill is invoked in contexts the user did not explicitly intend. In this skill, that matters because the capability is tied to evading AI-detection systems, so overbroad activation can steer normal editing requests into policy-evasive behavior.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The skill description explicitly advertises rewriting text so it can pass GPTZero, Turnitin, and similar detectors, which is a direct evasion objective rather than a neutral editing function. This enables academic-integrity abuse, fraud, and deliberate circumvention of safeguards designed to identify AI-generated content.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The trigger section actively instructs use of the skill when the goal is to bypass AI-content detection, operationalizing the evasion behavior instead of merely mentioning it. Because triggers define when the agent should act, this makes misuse easier and more likely in real-world deployment.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The markdown example sends user-provided text to an external API but only notes that network access is required; it does not clearly warn that the text leaves the local environment and is disclosed to a third party. If users submit sensitive drafts, proprietary material, or personal data, this can cause unintended privacy and confidentiality exposure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The Windows example posts the full text content to GPTZero without an explicit privacy disclosure, so users may assume the operation is local when it is not. In a text-rewriting workflow, inputs may contain unpublished documents, student work, or confidential business content, making silent external transmission risky.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.