Back to skill

Security audit

Product Description Writer

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward e-commerce copywriting skill with disclosed optional local helper scripts and no evidence of hidden access or harmful behavior.

Safe to install for product description work. Review generated claims before publishing, especially certifications, health or performance claims, and competitor-derived wording. If using the optional scripts, point them only at files you intend the skill to read or create.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
76% confidence
Finding
The trigger conditions are broad enough to activate on generic rewriting, competitor listing, or spec-sheet transformation requests that may fall outside a narrow product-description use case. Overbroad activation can cause the wrong skill to engage on unrelated or sensitive content, increasing the chance of unintended data handling, misleading outputs, or policy bypass through context confusion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.