Back to skill

Security audit

opinion-to-article

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed writing workflow that uses web search to turn a user’s own viewpoint into an article or script, with no evidence of hidden access, persistence, or destructive behavior.

Before installing, expect the agent to use web search and ask for confirmation of your core viewpoint before drafting. If you only want a generic writing assistant, the broad triggers may activate this more opinion-focused workflow, so rename or narrow the trigger phrases if your skill system supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases include very generic requests such as '写文章' and '做脚本', which can cause the skill to activate for ordinary conversations unrelated to this specialized workflow. Over-broad activation increases the chance of unintended routing, causing user requests to be handled under the wrong policy and potentially producing inappropriate web-search-driven content when the user did not ask for it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.