Back to skill

Security audit

Wenchang Router

Security checks across malware telemetry and agentic risk

Overview

This skill is a content-workflow router that recommends the next Wenchang step and includes explicit gates before user-impacting actions.

Before installing, understand that this skill is meant to choose the next step in a Wenchang publishing workflow, not to produce or publish content itself. Review its recommendations before running any downstream skill that uploads assets, rewrites URLs, pays for generation, or publishes externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description says to use the skill whenever the user gives many different artifact types or asks what should run next across numerous platforms, creating a very wide trigger scope. It does not provide explicit exclusion conditions or negative examples, so the router could be invoked for general content assistance rather than only for a narrowly defined routing task.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The only user-facing instruction is written entirely in Chinese and provides no indication that other languages are supported or that the locale is intentionally restricted. This creates a natural-language policy concern because the skill appears to require a specific language without offering user choice or documenting a justified regional scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.