Back to skill

Security audit

podcast-chat-prep

Security checks across malware telemetry and agentic risk

Overview

This markdown-only skill does not run code, but it explicitly encourages using podcast transcripts to appear more knowledgeable than the user is and lacks guardrails for privacy and reputational misuse.

Review this skill carefully before installing. It is not a technical malware risk, but it should only be used for transparent study, research, or content preparation with transcripts you have the right to process. Avoid using it to pretend firsthand familiarity, attack guests with decontextualized contradiction claims, or process private audio without consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README instructs users to upload or feed podcast transcripts into third-party transcription and AI services, but it provides no warning about privacy, consent, copyright, or data retention risks. This is dangerous because transcripts may contain personal data, unpublished material, or licensed content, and users may unknowingly disclose it to external providers.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill promotes cross-episode stance tracking, persona profiling, and identifying when a guest 'changed their mind' without any safeguards against reputational misuse or overclaiming. This can encourage users to generate potentially misleading profiles or decontextualized judgments about real people, creating harassment, defamation, or privacy risks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill metadata includes broad natural-language triggers such as '帮我快速了解这个播客' and '播客笔记', which are common requests that could overlap with many benign summarization tasks. This increases the chance of unintended activation and could route users into a workflow explicitly optimized for '没听过也能深度聊天' and '假装听过', enabling deceptive social use without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions describe several overlapping situations but do not clearly define boundaries for when the skill should not activate, especially for generic requests like extracting quotes, making notes, or preparing post-interview content. In context, the ambiguity is more concerning because the skill is designed to produce conversation ammunition and materials for appearing knowledgeable without actually listening, so accidental activation can facilitate misleading or manipulative use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill openly frames its value as helping users create materials so they can 'deeply chat' about podcasts they have not listened to and even says '我想假装听过这个播客'. Without warnings or safeguards, this normalizes deceptive social use and packages transcripts into persuasive talking points, internal jokes, and persona summaries that can be used to misrepresent familiarity or trustworthiness. The surrounding context makes this more dangerous because the workflow is specifically optimized for believable social performance rather than neutral summarization.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.