视频号爆款 IP 脚本工厂

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese video-script generation skill with an optional model API call and no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable sending the prompts and content you provide to the configured model endpoint. Use MODEL_MOCK_RESPONSE for offline testing, and avoid placing unrelated secrets in input files passed through the CLI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documentation explicitly describes executable entrypoints, build/run steps, and use of environment variables for model API keys, which indicates code can access network services and secrets despite no declared permissions. This creates a trust and transparency gap: a user or platform may assume the skill is low-privilege while it can actually make outbound requests and consume sensitive credentials.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The system prompt is entirely in Chinese and frames the assistant role/output expectations in Chinese without any mechanism to detect or honor the user's preferred language. This can override user intent, reduce accessibility, and create compliance or usability issues in multilingual deployments, even though it is not a direct code-execution or data-exfiltration risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal