Back to skill

Security audit

Wenchang Review

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward draft-review and editing guide with no hidden execution, data access, or persistence behavior.

Installers should expect this skill to review drafts and may see Chinese platform references and author contact information. It does not appear to run code, access private data, or make changes outside the chat response.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
This markdown file contains user-facing natural language that partially forces Chinese content ('Follow/关注作者' and the WeChat account reference) without any opt-in or language preference mechanism. The policy for this audit flags language or locale constraints when a specific language is imposed without user choice.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The instruction text is written as a direct Chinese-language prompt, which implies the skill operates in Chinese by default. There is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.