Back to skill

Security audit

Sustoiclab Nvc非暴力沟通工具箱 · Su's StoicLab

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only communication coaching skill with no executable code, network use, credential handling, or persistence; its main caveat is a style reference that should not override the user's requested voice.

Safe to install for communication coaching. Users should be aware that one optional style reference is written as direct Marshall Rosenberg voice imitation; prefer using it as NVC-inspired tone guidance and let explicit user tone requests take priority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file explicitly instructs the agent to produce content in a specific persona and tone ('以马歇尔·卢森堡的声音产出内容') without any indication that the user has requested or consented to that style. This can override user preference, reduce transparency, and encourage imitation of a real person’s voice, which is a prompt-safety and policy concern even though the content is otherwise nonviolent and communication-focused.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.