Back to skill

Security audit

ru-text

Security checks across malware telemetry and agentic risk

Overview

This skill is a Russian writing and typography helper whose broad activation can affect Russian text style, but it does not request sensitive access, persistence, network use, or automatic file mutation.

Install this if you want Russian typography and editorial defaults applied broadly. Avoid it, or disable implicit/always-on invocation, if you need exact preservation of Russian punctuation, number formatting, quotes, or locale-specific style in every response.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill declares broad, common Russian phrases like «проверь текст», «поправь», and «отредактируй» as triggers, which can match many normal user requests. This can cause unintended activation and make the assistant apply this skill in contexts where the user did not explicitly choose it, altering outputs or overriding other more appropriate behaviors.

Vague Triggers

High
Confidence
97% confidence
Finding
The metadata sets `always: true`, which makes activation effectively global rather than user-directed. In combination with the skill’s instruction to silently modify all Russian output, this creates an overly broad interception surface that can unexpectedly influence unrelated tasks, cause hidden output transformations, and interfere with user intent.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill instructs the agent to silently enforce a specific Russian typographic and locale style on all Russian output, including quote marks, spaces, punctuation, and numeric formatting, without requiring user opt-in. While not directly malicious, this is a policy-overreach issue because it can modify content presentation, meaning, or compliance-sensitive formatting in contexts where the user did not request editorial normalization.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.