Back to skill

Security audit

Wechat Article Writer Free

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk writing assistant skill that mainly generates or edits WeChat-style article drafts, with some file-save and optional command guidance to watch for.

Before installing, understand that this skill is meant for article drafting and may create or modify local draft/config files. Use it deliberately for公众号 or long-form content work, confirm filenames such as draft.md before saving, and be cautious with optional external model API keys or command-line helper steps because they are not needed for the core Markdown-based workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger condition is broad enough to match ordinary writing or marketing requests, which can cause the skill to activate unexpectedly in contexts where the user did not intend tool-assisted file generation or modification. In an agent ecosystem, overbroad auto-invocation increases the chance of unintended writes, confusing behavior, or inappropriate application of the skill to unrelated prompts.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill describes exporting or saving draft files without clearly warning the user that local files may be created or overwritten. Even though the action is low risk in this writing context, silent file writes can still lead to accidental data loss, workspace clutter, or modification of unintended files if paths are inferred or reused.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.