Back to skill

Security audit

播客

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but its podcast purpose is mixed with broader media tasks while requesting generic file and command authority.

Review this skill carefully before installing. It may be appropriate only if you are comfortable granting an agent read/write/exec authority for media-related tasks and you will supervise command execution yourself. Prefer a revised version that narrows invocation to podcast audio or transcripts and lists exact allowed commands, inputs, outputs, and data handling.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a podcast chaptering tool, but the description expands its scope to unrelated media-processing functions such as video processing, audio editing, media conversion, and voice generation. This kind of scope inflation can cause an agent to invoke the skill for requests outside its intended safety envelope, increasing the chance of inappropriate tool use and unsafe command execution.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation claims command execution is limited to a whitelist, but no whitelist, allowed command set, or enforcement mechanism is actually defined in the skill file, while the manifest advertises generic exec capability. This creates a dangerous mismatch where operators may assume strong restrictions exist when the agent could in practice run arbitrary commands in response to loosely scoped tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill uses broad activation guidance that goes beyond podcast chaptering and may match many unrelated user requests. In an agent environment with read/write/exec tools, ambiguous routing increases the risk that the skill is selected for tasks it was not designed to handle, potentially exposing file, command, or API operations unnecessarily.

Vague Triggers

Low
Confidence
84% confidence
Finding
The usage guidance is truncated and nonspecific, so it fails to constrain when the skill should or should not be used. This ambiguity is less severe than the earlier scope inflation, but it still increases the likelihood of accidental over-invocation and unsafe tool access in borderline contexts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.