Back to skill

Security audit

Storytelling And Narrative

Security checks across malware telemetry and agentic risk

Overview

This is a content-craft skill for structuring truthful social-media stories, with no executable code or hidden data-handling behavior found.

Before installing, understand that this skill may activate for broad social-content improvement requests. It is best used when you specifically want narrative structure, emotional framing, or story-arc work, and users should still review any downstream publishing steps before content goes live.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The eval trigger 'Help me turn this flat update into a story' is broad and resembles a common user request that could match many unrelated writing or content skills. In a multi-skill agent system, overly generic invocation language can cause unintended activation collisions, leading this skill to intercept requests outside its intended scope and potentially bypass more appropriate routing logic.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example 'Write a story-driven post for us' is ambiguous because it can mean either narrative strategy or simply drafting social copy. That ambiguity increases the chance that this skill activates when a format-specific writer should handle the request, creating misrouting and unpredictable downstream behavior in an agent orchestration environment.

Vague Triggers

Low
Confidence
80% confidence
Finding
The phrase 'This post feels flat -- how do I make it land?' is a very generic content-improvement request that could apply to hooks, tone, structure, editing, design, or platform optimization. Because the skill is meant for narrative craft specifically, such a broad trigger can cause accidental activation and routing conflicts, though the impact is somewhat limited because the domain remains social content rather than a sensitive operational capability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.