Back to skill

Security audit

播客章节工具免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed podcast chaptering helper that reads or generates transcript-derived drafts and does not show hidden publishing, exfiltration, persistence, or destructive behavior.

Install only if you are comfortable letting the agent read podcast transcripts/audio-derived files, run local transcription commands if requested, and write draft chapter or show-notes outputs. Keep prompts explicit about which file to process and review generated notes before sharing or publishing them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill presents itself as a narrowly scoped podcast chaptering tool, but the implementation notes describe broad create/query/modify/delete/import/export operations and runtime-configurable behavior. That mismatch can enable overbroad agent actions, increasing the risk that a caller or prompt injection causes unintended file or data operations beyond the expected chapter-generation scope.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger and execution descriptions are overly broad and do not define clear activation boundaries, approved intents, or disallowed operations. In an agent setting, vague trigger conditions make accidental invocation or prompt-induced misuse more likely, especially when the skill has read/exec/write tools available.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The natural-language invocation example is permissive and lacks a distinct trigger syntax or boundary conditions, so normal conversational text could unintentionally activate the skill. In tool-using agents, this raises the chance of unauthorized reads, writes, or shell-assisted workflows being initiated from ambiguous prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.