降龙十八掌

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk creative writing and SVG illustration helper with no evidence of hidden access, persistence, data collection, or destructive behavior.

Installers should expect this skill to trigger broadly when discussing 降龙十八掌 move names. That may be noisy in general conversation, but the reviewed artifact does not show hidden behavior, data access, persistence, or unsafe commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger examples include broad phrases like "施展降龙十八掌" and "降龙掌法", which can cause the skill to activate on casual mentions rather than clear user intent to invoke it. This can lead to unintended tool use and irrelevant responses, especially because the skill immediately proceeds to generate SVG content.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation condition triggers on any mention of a move name, which is ambiguous and likely to fire during general discussion, quotation, or comparison rather than an actual request for execution. In this skill, accidental activation is more significant because it invokes `show_widget` and produces a structured multi-step output automatically.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal