html-text-editor-lite

Security checks across malware telemetry and agentic risk

Overview

This skill transparently adds a local, lightweight text editor to user-chosen HTML files without hidden network, credential, or destructive behavior.

Install if you want an assistant to make static HTML pages text-editable in the browser. Review the generated editable HTML before sharing it, export a clean copy for permanent changes, and avoid using --inplace or --force unless you intentionally want to overwrite an existing file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises multiple broad natural-language triggers such as 'edit the text myself', 'make this HTML editable', and similar Chinese phrases. These phrases are generic enough that the skill may be invoked in situations where the user did not specifically want this transformation, causing unintended modification of HTML artifacts or use of the wrong editing workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal