Back to skill

Security audit

水晶玄学小红书合规文案生成器

Security checks across malware telemetry and agentic risk

Overview

This is a content-writing skill for crystal-themed Xiaohongshu posts; it has questionable metaphysical wording but no hidden execution, data access, persistence, or destructive behavior.

Install only if you want a crystal-spirituality copywriting assistant. Review generated posts before publishing, especially where they imply effects on mood, sleep, energy, cleansing, or platform compliance, and add clearer personal-experience or cultural-context disclaimers if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The example note makes repeated causal claims about crystals affecting mood, sleep, focus, and 'aura matching,' which crosses from lifestyle copy into unsupported metaphysical guidance. In this skill context, that is dangerous because the manifest explicitly frames the content as non-superstitious, creating a mismatch that can mislead users and platforms about the nature of the generated output.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
This section instructs users on aura manipulation, receiving/releasing energy, and purification practices as if they have functional effects. That is risky because it operationalizes superstition while the skill description claims to avoid it, increasing the chance of deceptive or policy-violating content generation at scale.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.