Back to skill

Security audit

TalonForge AI CEO Persona (EN/AR)

Security checks across malware telemetry and agentic risk

Overview

This non-executable AI CEO persona is not malicious, but it asks an agent to create persistent operating files and run broad business workflows without clear approval limits.

Review before installing. Use only with explicit human approval for financial actions, public launches, contracts, account changes, and customer-impacting decisions. Decide where generated memory and operating files may be written, what data must never be stored, and how to remove or roll back the generated files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill frames itself as bilingual EN/AR and Arabic-first by default, including Gulf-market positioning, without clearly indicating that this locale behavior is optional or user-configurable. This can steer agent behavior, language choice, market assumptions, and generated business actions in ways the user may not have explicitly requested, creating a consent and scope-control problem rather than a direct exploit.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The setup instructions say initialization will create multiple files such as SOUL.md, AGENTS.md, MEMORY artifacts, safety rails, dashboards, and launch materials, but the description does not prominently warn the user that persistent local state and operational artifacts will be created. This is dangerous because users may trigger initialization without understanding that the skill will write multiple files, establish memory/state persistence, and potentially shape future agent behavior beyond the current session.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.