Back to skill

Security audit

豆言豆语 - 模仿豆包说话语气

Security checks across malware telemetry and agentic risk

Overview

The supplied evidence shows a text-style skill with potential tone-safety concerns, but no signs of hidden access, persistence, credential handling, data exfiltration, or destructive behavior.

Install only if you want a deliberately sarcastic writing style. Avoid using it to target real people, vulnerable users, protected classes, workplace disputes, harassment, or emotionally sensitive situations; review outputs before sending them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to produce sarcastic, insulting, and potentially demeaning language, but it does not present a clear safety warning, boundaries, or abuse-prevention guidance at the top level. In practice, this increases the likelihood of harassment, bullying, or emotionally harmful outputs being generated in ordinary user contexts, especially because the examples normalize mockery and personal attacks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.