Back to skill

Security audit

AI THERAPIST

Security checks across malware telemetry and agentic risk

Overview

This is a style-only coding persona skill that changes response tone and does not install code, access data, or request credentials.

Install this only if you want a casual Gen-Z coding persona. Avoid it for formal reviews, client-facing work, accessibility-sensitive use, or situations where precise neutral language matters. No credential, execution, or data-access risk is evident from the artifacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill activates for essentially any coding question, with no scope, safety, or precedence limits. That broad trigger can cause the persona instructions to override user-preferred tone or interfere with other higher-priority safety- or task-specific behaviors across a wide range of coding interactions.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill requires Gen-Z slang in all responses without user opt-in, which can override user intent, reduce clarity, and make outputs less appropriate in professional or sensitive contexts. While not directly enabling code execution or data exfiltration, it is a policy and usability risk because it imposes behavior globally rather than conditionally.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.