Back to skill

Security audit

Humanizer

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed writing-editing skill that rewrites text to sound less AI-generated, with no hidden code, network behavior, credential access, or persistence.

Install only if you want an agent to rewrite text in a more human-sounding style. Review changes before applying them to important files, and do not use it where disclosure of AI assistance, authorship, or personal voice matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill is granted Write and Edit capabilities, but the instructions do not require explicit confirmation before modifying user files. In practice, that can lead to silent or unintended changes to drafts, documents, or repository content, especially because the skill is framed as an editing tool and may be invoked on existing files.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill explicitly tells the agent to make text appear more human-written and to 'add soul,' including first-person perspective, opinions, and personality. That crosses from ordinary copyediting into impersonation risk: it can help users present AI-generated text as if it were authentically written by a human, which is deceptive in academic, professional, or trust-sensitive contexts.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.