superword

Security checks across malware telemetry and agentic risk

Overview

This is a Word document guidance skill with no executable code, though its description contains a stray nonsense trigger phrase that should be cleaned up.

Safe to install for Word/DOCX workflows. The publisher should remove the stray nonsense phrase from the description so the skill is selected only for document-related tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description contains a nonsensical, overly broad trigger fragment ('ncaa staff e ο om reputation yong qatarhend [unused864] merge obama suites sections file') that can cause the skill to match unrelated prompts. In an agent-routing context, this expands activation scope unpredictably and may route non-Word tasks into a powerful document-editing skill, increasing the chance of inappropriate tool use or prompt-trigger abuse.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal