Back to skill

Security audit

Ai Writing Style Cloner

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed writing-style analysis and generation helper that stores local JSON style profiles, with privacy and overwrite caveats users should understand.

Before installing, treat submitted writing samples as content processed by the underlying model provider and avoid unpublished, private, or third-party material unless you have permission. Be aware that saving a profile for the same author_id overwrites the existing local JSON profile, so keep backups or use distinct IDs when preserving versions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill persistently stores style fingerprints and explicitly overwrites existing files, but the description does not prominently warn users that prior data may be replaced. This can lead to unintended loss or silent modification of persisted author profiles, especially in multi-author or repeated-use contexts.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill sends uploaded writing samples to an LLM for analysis, but it does not clearly warn users that potentially sensitive authored content may be transmitted to an external or platform model. This creates a real privacy and data-governance risk, especially for unpublished drafts, proprietary materials, or personal writing samples.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.