Back to skill

Security audit

去除文本中

Security checks across malware telemetry and agentic risk

Overview

This skill is openly a text humanizer, but it requests command execution and broad file capabilities that are not necessary for simple rewriting and frames the output as hiding AI authorship.

Install only if you intentionally want an AI-authorship humanizer and can keep its use within your disclosure and integrity requirements. Treat the read/write/exec declarations as overbroad for this purpose; avoid granting command execution or unrestricted file access unless the platform lets you constrain them and you have a specific, reviewed workflow that needs them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a narrow text-humanizing tool, but the documentation advertises broader file handling, API integration, and command-execution abilities. This mismatch increases the risk that operators or downstream agents grant the skill unnecessary privileges, enabling misuse beyond its declared purpose.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
System command execution is a high-risk capability and is not justified by the stated purpose of rewriting text to sound more human. If exposed to an agent or workflow, this can expand a simple editing skill into arbitrary code execution, with potential for data loss, persistence, or host compromise.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
General read/write access is broader than necessary for a skill whose purpose is simple text rewriting. Overbroad file permissions can expose sensitive local data or allow unintended modification of user files, especially in autonomous agent environments.

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
The documentation claims external API integration without clearly tying it to the narrow humanizer function. Unnecessary network access can enable data exfiltration, unreviewed third-party processing of user content, or expansion of the trust boundary without informed consent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad and vague, suggesting use in many generic AI, workflow, and automation contexts unrelated to the skill's advertised purpose. This increases the chance of accidental triggering in inappropriate situations, causing overreach and unnecessary exposure of privileged capabilities.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The use-case labels are overly generic and overlap with common content-generation and processing tasks outside a narrowly scoped humanizer. In an agentic environment, ambiguous scope can cause the skill to be selected too often, increasing misuse risk and exposing file/exec/network powers unnecessarily.

Ssd 2

Medium
Confidence
90% confidence
Finding
The skill is explicitly framed as making text no longer appear AI-generated, which promotes concealment of authorship rather than ordinary editing. That framing can facilitate policy evasion, academic or professional misrepresentation, and deceptive content laundering at scale.

Ssd 2

Medium
Confidence
89% confidence
Finding
The capability and scope sections reinforce the evasion objective by describing transformation of content to disguise AI authorship. In context, this is more dangerous because the skill is packaged for agent use, making large-scale deceptive rewriting easier and more automated.

Ssd 4

Medium
Confidence
87% confidence
Finding
The before/after example gives a practical recipe for stripping stylistic signals associated with AI-written text, effectively operationalizing concealment guidance. Examples like this lower the barrier to misuse by teaching users how to systematically evade AI-authorship detection heuristics.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.