Back to skill

Security audit

Gov Service Wechat Layout

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed WeChat government-service article layout helper with local templates and simple color-replacement scripts, with no evidence of hidden access, exfiltration, or unsafe automation.

Installers should treat this as a layout/template tool: review the generated HTML before publishing, replace all placeholders with verified official values, and avoid fabricating phone numbers, policy references, QR codes, or links. Run the included scripts only on files you intend to modify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The README advertises very generic trigger phrases such as '给这篇…排版' and '套用模板/换色', with no explicit boundaries to ensure the skill only activates for the intended government WeChat formatting workflow. In an agent environment, broad triggers can cause unintended invocation on unrelated formatting requests, leading to misrouting, incorrect HTML generation, or interference with other skills handling general writing or publishing tasks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.