Back to skill

Security audit

Viral Note Imitation Writer

Security checks across malware telemetry and agentic risk

Overview

The skill is a simple external API wrapper for marketing-note rewriting, but it explicitly promotes bypassing duplicate detection and sends user content to a third-party service with limited privacy disclosure.

Install only if you are comfortable using a third-party rewriting service and sending the submitted text, product details, and selling points to wsdsocial.com. Do not provide confidential, personal, regulated, or unauthorized copyrighted material, and avoid using it to evade platform rules or repost close imitations of others' content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad enough to match generic requests like 'rewrite' or 'viral,' which can cause the skill to activate when the user did not intend to send content to this external service. In this skill, unintended invocation is more dangerous because activation may transmit user-provided text, product details, or marketing content to a third-party API without clear, specific consent at the moment of use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to submit a reference note, product information, and selling points to an external API but does not warn that this data leaves the local environment. This creates a real data-handling risk because users may provide proprietary drafts, campaign plans, customer information, or copyrighted third-party content without understanding that it will be transmitted to a remote service.

Ssd 2

Medium
Confidence
93% confidence
Finding
The skill explicitly markets itself as a way to 'bypass duplicate detection,' which indicates intent to help users evade platform integrity controls and reuse viral content with superficial transformation. In context, this increases abuse risk because the tool is optimized for imitation of third-party content and evasive rewriting, which can facilitate plagiarism, spam, and policy circumvention at scale.

Ssd 2

Medium
Confidence
93% confidence
Finding
The core instructions repeat the goal of generating content that matches a reference tone while helping users avoid duplicate detection, reinforcing that evasion is a functional objective rather than incidental wording. This makes the skill more dangerous because the risky behavior is embedded in the main operating instructions, not just metadata, increasing the likelihood of misuse for content laundering and spam campaigns.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.