Back to skill

Security audit

Report to Article

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language writing workflow skill for reorganizing reports into articles, with no executable code or hidden data access found.

This skill is appropriate if you can read Chinese or have a Chinese-capable agent. Before installing, note that long-report workflows may create or append to an output file and run simple local text-count checks to verify nothing was lost; review the final article to ensure the original report's facts and links were preserved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The skill is written entirely in Chinese with no language selection or fallback, which can cause users or downstream agents that do not read Chinese to misunderstand critical operating constraints. In a security-sensitive or workflow-automation context, this increases the chance of incorrect execution, missed safety boundaries, or silent misuse due to operator confusion rather than explicit malicious behavior.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.