Back to skill

Security audit

职场沟通写作免费版

Security checks across malware telemetry and agentic risk

Overview

This is a workplace-writing helper, but it requests command execution and write capability that are not needed for its stated purpose.

Review before installing. The skill text itself appears to be a normal workplace communication template, but it should not need command execution or broad write access. Prefer a version that removes exec, explains any write access, and omits unnecessary API-key setup unless your agent platform requires it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill is a template-based writing assistant, but its manifest requests `exec` alongside `read` and `write` without any documented need to run commands. Over-privileging an agent skill increases the attack surface: if the skill is ever extended, misused, or invoked by a broader agent workflow, command execution could enable unintended system access or abuse unrelated to its stated purpose.

Intent-Code Divergence

Low
Confidence
85% confidence
Finding
The dependency and runtime sections suggest shell-based API key setup and an MD+EXEC capability model even though the skill behavior is described as a communication-writing helper. This mismatch can normalize unnecessary execution privileges and encourage operators to provision broader access than needed, increasing exposure if the surrounding agent environment is compromised or the skill is repurposed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.