anything-to-html

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable formatting skill that turns deliverables into single-file HTML, with some usability caveats but no evidence of malware, credential access, persistence, or hidden behavior.

Install this if you want polished HTML deliverables. Before using it for sensitive or offline work, ask the agent to avoid CDN resources and produce a fully self-contained file; also state the desired output language and format if you do not want Chinese or HTML by default.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill’s trigger criteria are extremely broad and explicitly instruct the agent to prefer this skill for almost any request involving a deliverable. This can cause unintended activation, override more appropriate skills, and expand the skill’s influence into contexts where HTML generation is unnecessary or risky, increasing the chance of policy or workflow misuse.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The instruction that Chinese content should be preferred by default imposes a language policy without checking the user’s requested language. In multilingual or English-language workflows, this can lead to undesired output, user confusion, and noncompliance with expected language behavior, especially when the generated artifact is intended for external sharing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal