General Writing

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal writing-assistance skill with citation-formatting instructions, not a tool that runs code, reads files, persists data, or handles credentials.

Install this as a general writing helper, but do not ask it to include private files, secrets, or sensitive internal information in citations, links, or source lists. Treat generated citations as formatting assistance and verify sources before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest grants a very broad capability to write "all kinds of materials" without any activation boundaries, domain limits, or safety constraints. In an agent system, this increases the chance the skill is invoked in unintended contexts and can be used to generate sensitive, deceptive, or policy-violating content under the guise of a generic writing function.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The instruction block repeats an unrestricted writing mandate and focuses on formatting and citation behavior rather than limiting what the skill may help produce. Because the skill is effectively a general-purpose content generator, it can be repurposed for harmful persuasion, misleading sourced-looking output, or other unsafe tasks if invoked broadly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal