Back to skill

Security audit

文档对比工具

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward document comparison skill; the main caution is that compared documents may be included in the generated HTML output.

Use this for documents you are allowed to process with an AI assistant. Avoid pasting secrets, credentials, regulated personal data, or confidential contracts unless you have approval, and treat any generated HTML file as containing the underlying document content unless you choose a summary-only output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to paste complete old and new documents, yet it provides no warning that potentially confidential text will be processed in full and then embedded into a generated single-file HTML artifact. This creates a realistic risk of sensitive business, legal, personal, or regulated data being unnecessarily exposed, retained, shared, or redistributed through the output file.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.