Back to skill

Security audit

story-short-analyze

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed short-story analysis workflow that creates local analysis files and metadata, with no hidden execution, credential access, networking, or persistence beyond its output directory.

Install only if you want a Chinese short-fiction analysis pipeline that will create a local 拆文库/{书名}/ directory, copy or save the source text there, and produce reusable analysis for later writing workflows. Be aware that some genre references encode strong market and ideological assumptions, so review generated reports if you need neutral literary criticism.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises numerous broad natural-language trigger phrases such as '分析这篇短篇' and similar generic requests, which can cause the skill to activate when a user did not specifically intend to invoke it. Because this skill performs a heavy multi-stage pipeline that reads, analyzes, and writes files under project directories, unintended invocation can lead to unnecessary processing, accidental file creation/overwrite workflows, and confusing cross-skill routing behavior.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
These lines prescribe a fixed ideological stance and deference to a specific contemporary authority as a writing constraint, rather than presenting it as optional context or platform-specific content guidance. In an agent skill, this can bias outputs, suppress user autonomy, and cause politically steered analysis or generation even when the user did not request that framing.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.