Back to skill

Security audit

公众号文案创作

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its stated WeChat copywriting purpose, but it asks for sensitive personal writing samples without privacy guidance and injects an undisclosed promotional contact line from its script output.

Review before installing. Use a revocable RedFox API key, expect keyword queries to be sent to redfox.hk, and do not provide diaries, private notes, confidential drafts, customer data, or proprietary writing samples unless the skill adds clear handling and deletion guidance. Be aware that the bundled script includes an undisclosed promotional contact line in its output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs use of environment variables and outbound network access to a third-party service, but does not declare corresponding permissions. Undeclared capabilities reduce transparency and can bypass user/admin expectations about what the skill can access, especially where API keys and external data flows are involved.

Tp4

High
Category
MCP Tool Poisoning
Confidence
81% confidence
Finding
A mismatch between declared behavior and actual behavior is a trust and safety issue because users may authorize or rely on the skill under false assumptions. If the skill also injects undisclosed promotional content or fails to perform the promised analysis, it can manipulate outputs and exfiltrate value to a third party without clear disclosure.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance is broad enough to match common user phrasing such as generic requests about writing, articles, or recommendations, which increases the chance the skill is triggered outside the user's clear intent. In an agent ecosystem, over-broad triggers can cause unintended access to external data sources or generation behavior, especially when the skill can process uploaded writing samples and produce publish-ready content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README encourages users to upload personal writing samples for style analysis but does not warn about privacy, retention, third-party processing, or the risk of including sensitive personal or proprietary text. This can lead users to submit confidential data without informed consent, particularly because writing samples may contain personal identifiers, business information, or unpublished content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill asks users to provide diary, note, or journal-style writing samples for style imitation without any privacy notice, minimization guidance, or handling disclosure. This is dangerous because such samples often contain highly sensitive personal data, and users are not warned about risks or given constraints on what to share.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly solicits private diary/note content and then processes it to learn and reproduce the user's writing style. In context, this increases privacy risk because intimate writing can reveal health, relationships, location, finances, or other sensitive attributes that are unnecessary for the core function of generating public-account copy.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.