Identity Shift

Security checks across malware telemetry and agentic risk

Overview

This is a text-only self-reflection coaching skill with emotionally intense prompts, but no evidence of hidden execution, data exfiltration, persistence, or destructive behavior.

Install only if you want an intense self-reflection coaching flow. Avoid sharing details you would not want in the chat history, pause or skip questions that feel too personal, and do not use this as therapy or crisis support; seek qualified help for severe distress, self-harm thoughts, abuse, or acute mental-health concerns.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation description uses very broad life-problem triggers such as repeated failure, confusion about life direction, planning, and self-exploration, which are common user states and can cause the skill to be invoked in situations far beyond a narrowly scoped use case. In context, this is more dangerous because the skill then drives users into intense emotional disclosure and identity-reframing without clear safeguards, increasing the chance of inappropriate or overbroad deployment.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill explicitly prompts for highly sensitive emotional material, including pain, anger, jealousy, anxiety, family dynamics, regret, and mortality-themed reflection, but provides no warning, consent checkpoint, privacy notice, or escalation guidance. This is dangerous because users may disclose crisis-relevant or trauma-related content in a setting framed as a forceful coaching interaction rather than a safety-aware support flow.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly pushes users into discussing pain, anger, jealousy, anxiety, regret, and identity collapse using a confrontational style, but provides no safety notice, opt-out, de-escalation path, or crisis guidance. In a self-help coaching context, this can worsen distress, trigger rumination, or produce harmful advice for emotionally vulnerable users, especially because the prompt instructs the agent to reject superficial answers and intensify probing.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal