Back to skill

Security audit

热点追踪,写作画像自定义,创作发布一体化自媒体内容创作助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent self-media writing assistant, but its publishing workflow can create Tencent Docs and WeChat public-account drafts through connected accounts without a clear final approval gate.

Install only if you intend to connect Tencent Docs or WeChat publishing accounts. Before using publish or sync features, require the agent to preview the exact title, content, destination account, and service action, then wait for your explicit approval. Review the optional external MCP helper before installing it, and avoid sending confidential or regulated content to connected third-party services unless you have approved that transfer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The usage example for publishing omits the documented fact-checking step and normalizes going from drafting directly to public-channel publication. In a content-generation skill, this increases the chance of distributing inaccurate, defamatory, or noncompliant material, especially because the workflow otherwise presents fact-checking as a required safeguard.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The README advertises publishing to WeChat and syncing to Tencent Docs, but it does not warn users that article drafts, prompts, profile data, or sensitive workspace content may be transmitted to third-party services. In an agent setting, lack of disclosure can lead to unintended external data exposure when users assume operations remain local.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill performs external writes by creating Tencent documents and WeChat public-account drafts, but it provides no user-facing warning or explicit consent step before transmitting content to third-party services. This is dangerous because generated or user-supplied content may be sent off-box or persisted externally without the user's clear understanding, creating privacy, confidentiality, and unintended publication risks.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The skill references storing writing profiles on a local filesystem without warning users that stylistic preferences and derived profile data may be persisted. While local storage is less severe than remote exfiltration, undisclosed persistence can retain sensitive preferences, proprietary writing patterns, or reference-derived data longer than the user expects.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.