Back to skill

Security audit

Soulcraft Identity

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only skill for drafting agent identity files, with no code execution or hidden access found.

Safe to install as a drafting aid. Review any generated SOUL.md before using it long term, especially autonomy rules, safety boundaries, and trigger phrases, so it does not encode behavior you did not intend.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains broad, natural-language phrases such as "agent identity" and "configure agent voice" that could easily appear in ordinary conversation, causing the skill to activate unintentionally. In an agent-building context, accidental invocation can redirect behavior, generate configuration artifacts the user did not request, or interfere with higher-priority instructions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.