Back to skill

Security audit

Cross Platform Repurposing

Security checks across malware telemetry and agentic risk

Overview

This skill gives content-repurposing instructions and reference examples, with no executable code or hidden data movement.

Installers should treat this as a content workflow skill, not an automation risk by itself. Review generated posts and scheduling handoffs before publishing, especially for regulated, sensitive, or brand-critical content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest says to run when the user says phrases like "repurpose this" or when the user "wants to fan content out," which is ambiguous and not tightly scoped to a specific workflow or context. Although several examples are provided, the catch-all phrasing broadens activation beyond clearly bounded triggers and could cause unintended invocation.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The file directs the agent to shift register by platform, including "LinkedIn more formal, TikTok looser," which prescribes communication style based on platform rather than user choice. This is a mild natural-language policy concern because it sets locale/style behavior unilaterally instead of offering an explicit user preference or opt-in.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.