Michael Polanyi

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk writing guidance skill with no hidden data access, network behavior, or privileged actions.

Install this if you want the assistant to rewrite advice in a more decisive, practitioner-style voice. Be aware it may influence broad advice or strategy answers and may lean on Chinese phrasing unless your agent adapts the examples to the user’s language.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description is broad enough to match many generic advice or strategy requests, which can cause the skill to activate outside its narrow intended scope. That creates a prompt-routing and policy risk: users may receive this skill's style constraints in contexts where a more precise, domain-specific, or safer skill should apply, degrading reliability and potentially bypassing intended guardrails for other workflows.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hardcodes Chinese-language response markers and examples as normative output structure without asking for user language preference. In mixed-language environments this can override user intent, cause unexpected language switching, and interfere with downstream tooling or safety behaviors that assume responses stay in the user's requested language.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal