Back to skill

Security audit

Novel Chapter Review

Security checks across malware telemetry and agentic risk

Overview

This novel-review skill appears legitimate, but it tells agents to run broad Python-based batch edits on manuscripts without enough safeguards.

Install only if you want the skill to help modify manuscript files, not just critique them. Before allowing edits, require an exact file list, backups, a dry-run or diff, and separate approval for any batch script or memory-file update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
This section expands the skill from analysis into direct content modification and batch rewrite operations, exceeding the declared purpose of producing scores, issue lists, and suggestions. That increases the chance an agent will make unintended bulk edits to user manuscripts without clear authorization boundaries or review checkpoints.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documentation explicitly instructs use of execute_code and Python scripts for bulk manuscript modification. Authorizing code execution for large-scale file changes in a review skill materially raises risk of destructive edits, unintended file access, and bypass of safer human-reviewed patch workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.