Back to skill

Security audit

Doc Coauthoring

Security checks across malware telemetry and agentic risk

Overview

This is a structured writing-assistant skill with no executable code, persistence, credential access, or hidden high-impact behavior.

Before installing, understand that this skill is designed for substantial documents and may ask for business or product context you provide. Avoid pasting sensitive material unless you are comfortable using it in the agent environment, especially if independent review tools or subagents are enabled. The author attribution and Chinese example are visible metadata/content, not hidden behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description says to use the skill when the user wants help "writing, shaping, reviewing, or iterating a document," covering a very wide range of everyday writing assistance without clear trigger boundaries or exclusion conditions. Because no explicit trigger phrases, scope constraints, or negative examples are provided, this could cause unintended invocation for many generic writing requests.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The description embeds Chinese text ("Follow/关注作者:微信公众号...") inside an otherwise English skill manifest, introducing a language switch that is not tied to user preference or a documented regional requirement. This can violate language/locale expectations because the skill presents content in a specific additional language without offering user choice.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The instruction at L1 is written as a direct requirement to collaborate in Chinese and does not indicate that other languages are supported. This can violate a language/locale policy when the skill constrains output language without user opt-in or documented justification.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.