Back to skill

Security audit

公文润色

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese official-document polishing skill with clear content boundaries and no evidence of unsafe execution, persistence, credential use, or data exfiltration.

Install this if you want a specialized assistant for Chinese official-document polishing. Be aware that generic requests like “polish this” may produce a formal public-document style, so use a general editing skill for ordinary prose, and review any generated official text for factual accuracy, tone, and whether added policy-style phrasing is appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are broad enough to match ordinary editing requests such as '优化', '润色', or '帮我提升', which can cause the skill to activate outside its intended narrow public-document context. This creates routing ambiguity and increases the chance that unrelated user content is processed under specialized instructions, degrading safety boundaries and potentially overriding more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.