lofter-fic-writer

Security checks across malware telemetry and agentic risk

Overview

This is a text-only LOFTER fanfiction writing aid; the flagged persona line appears to be sample story material, not hidden agent behavior.

This skill appears safe from an agentic-security perspective. Before installing, consider that it uses bundled fandom samples and is designed to produce high-click fanfiction, so review outputs for originality, platform rules, rating/content boundaries, and fandom norms before posting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file begins by imposing a fixed persona, name, body type, and personality traits on the agent without any user opt-in. This is a real prompt-safety issue because it can override user intent, constrain model behavior, and normalize identity/role-locking that may interfere with downstream instructions or create unsafe social-role dynamics.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal