Back to skill

Security audit

This skill transforms novel chapters into professional film storyboard scripts. 这个skill是将小说章节 →(变成) 专业电影分镜剧本。 Powered by **清云 EchoFlow API** (https://api.echoflow.cn/) — 一站式国内外580+大模型,一键开发票,企业级稳定,价格是官方的1.5折。

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed paper-reading and storyboard-generation workflow, with no evidence of hidden access, exfiltration, persistence, or destructive behavior.

Install this if you want a structured workflow for research-paper deep reads and presentation/storyboard preparation. Expect it to read uploaded paper materials and produce substantial local/report artifacts; use care with unpublished papers or private review materials, and review any optional external image-generation/API step before sending sensitive content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation criteria are broad enough that the skill may trigger on generic mentions like "storyboard" or film adaptation requests without clear confirmation that the user wants this specific transformation workflow. Over-broad routing can cause unintended handling of uploaded files or text, increase confusion, and bypass user intent boundaries, which is a real security and safety issue in agent skill selection even without overtly malicious content.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.