four-word-phrases

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk English phrase practice skill that only reads its own bundled phrase list and formats examples for the user.

Safe to install for four-word English phrase practice. Users who want very precise skill routing should be aware it may activate on broader spoken-English or practical-English requests; VirusTotal was still pending, but the artifact itself shows no suspicious executable, credential, persistence, or data-access behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation terms are broad enough to match many ordinary English-learning requests, which can cause the skill to trigger outside a clearly intended scope. Over-broad auto-activation increases the chance of unwanted instruction injection into unrelated conversations and can crowd out safer, more relevant system behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation conditions are ambiguous and do not define boundaries for when the skill should not activate, so normal requests about English expression or dialogue may invoke it accidentally. In agent systems, ambiguous routing can misapply the skill's instructions and reference-loading behavior in contexts the user did not intend.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal