Ai Content Rewriter

Security checks across malware telemetry and agentic risk

Overview

This skill is only a short marketing-style description for an AI content rewriting tool and shows no code, commands, credential use, persistence, or hidden behavior.

This appears safe to install from a security perspective, but it is very sparse. Users should not expect much behavior from it unless additional implementation exists elsewhere, and should review any future version that adds scripts, network access, credential use, or file operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is extremely generic and lacks clear activation criteria, scope boundaries, or operational constraints. In an agent environment, vague skills can be invoked too broadly or ambiguously, increasing the chance of unintended behavior, misuse, or overlap with higher-risk capabilities without user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal