Jupiter Quote

Security checks across malware telemetry and agentic risk

Overview

This appears to be an unfinished placeholder skill, not a dangerous one.

Install only if you are comfortable with this being a placeholder. It does not appear to contain harmful behavior, but it also does not currently provide the advertised Jupiter quote capability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description is still placeholder text and does not define when the skill should activate or what tasks it is intended to handle. In an agent environment, vague activation scope can cause the wrong skill to be invoked, leading to unsafe or unintended behavior, especially if the skill later gains scripts or privileged operations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The Overview section is unfinished and provides no concrete operational guidance, leaving the skill’s scope and expected usage ambiguous. This increases the chance of misapplication by an agent or user, which can become a security issue when unclear instructions interact with automation, external tools, or sensitive workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal