Back to skill

Security audit

多平台内容检测&安全改写

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese content compliance and rewriting assistant that uses web search for current policy checks and does not show hidden persistence, credential use, or unrelated file access.

Install this if you want Chinese marketing/content compliance review and rewriting. Be aware it will run web searches for current rules on each full check, and you should invoke it intentionally when you want that review rather than for ordinary editing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad, everyday review phrases such as asking to 'check' or 'review' text, which can cause the skill to activate on routine editing conversations rather than only when the user explicitly requests this specialized workflow. Because the skill mandates web searching and performs substantial rewriting, unintended invocation can expand data exposure to external search queries and override the user's expected interaction flow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad, generic Chinese terms such as '内容检查' and '广告法检查', which can easily overlap with ordinary user requests and cause the skill to activate unexpectedly. Because the skill performs policy-driven rewriting and mandates network-backed checking, accidental invocation could route unrelated content into a transformation flow the user did not explicitly request, creating consent and reliability issues.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.