Back to skill

Security audit

Fable Explainer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed educational writing helper that changes explanation style but does not run code, access data, or persist in the environment.

Install this if you want concept explanations in fable, analogy, or layered-teaching formats. Be aware it may activate on broad requests to explain or think through a concept, and treat the suggested Knowledge RAG install as a separate plugin decision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description uses broad natural-language triggers such as requests to explain something with a story, which can match many ordinary conversations beyond the intended specialized use case. In an agent environment, this can cause the skill to activate unexpectedly, override more appropriate behaviors, and create prompt-routing or instruction-precedence issues.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The alternate mode triggers include vague phrases like '帮我想想这个' or '给我讲讲这个概念', which are generic enough to appear in many unrelated conversations. This increases the chance of accidental invocation and unintended takeover of responses, especially when multiple skills compete for broad educational or brainstorming prompts.

Vague Triggers

Low
Confidence
79% confidence
Finding
The default guidance to use mode one when the user does not specify a mode makes activation behavior ambiguous and overly permissive. While lower severity than the explicit broad triggers, it still encourages the skill to claim loosely related requests without sufficient disambiguation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.