Danny_Skill

Security checks across malware telemetry and agentic risk

Overview

The skill text is a basic social-media publishing helper, but its package metadata describes a different AI content-analysis skill, so users may not know what they are installing.

Review carefully before installing because the visible package metadata does not match the actual skill text. Use it only if you want a Chinese-language short-video publishing helper, provide only media you intend to process, confirm where generated files will be written, and do not grant platform account access unless you separately trust the workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation example uses a very broad trigger phrase ('帮我发布到抖音和快手') without defining required inputs, confirmation steps, or boundaries on what actions the skill may take. In an agent setting, this can cause over-triggering and unintended processing of user media or publishing-related actions from ambiguous requests.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly handles user-provided images/video inputs and produces output files, but it does not warn users about file handling, storage, overwriting, sensitive media content, or verification of output paths. This increases the chance of unsafe handling of personal or proprietary media and may lead to accidental disclosure or destructive file operations in downstream tooling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal