Back to skill

Security audit

Wenchang Orchestrator

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed content-workflow orchestrator for Chinese and multi-platform publishing, with clear pauses before uploads, account actions, and publishing.

Install this when you want an orchestrator for Chinese-platform or multi-platform content production. Review any generated handoff packs and confirm manually before paid image generation, Computer Use prompt submission, uploads, URL rewrites, account actions, or publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instruction text is entirely in Chinese and directs generation of content assets for Chinese platforms without any indication that the user can choose another language or locale. This is a natural-language locale constraint and may violate language-choice policy unless the restriction is explicitly justified or made optional.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The manifest states delivery is coordinated for WeChat, Zhihu, Xiaohongshu, and Zhihu Idea, which implies a specific locale/platform orientation. There is no accompanying note that this skill is intended for Chinese-platform publishing or that users can opt into or out of this locale-specific workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.