Content Monetization

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only content-writing skill with broad trigger phrases but no code, credentials, account access, persistence, or hidden system behavior.

Installers should be aware that this skill may activate on fairly general writing or prompt requests. Use it when you want monetization-oriented content templates, and fact-check generated claims or platform advice before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill advertises very broad trigger phrases such as '帮我写文案', '写Prompt', and '今日内容', which overlap with common user requests and can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of prompt hijacking or unintentional routing, where unrelated requests are handled by this monetization-oriented skill and receive inappropriate or policy-risky guidance.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The activation section lists ambiguous examples like '写个脚本', '今天发什么', and '续写内容' without defining what requests should not trigger the skill. Because these phrases are generic and common across many domains, they can cause accidental invocation and make it easier for unrelated or sensitive requests to be funneled into this skill's templates.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal