知行合一

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese self-improvement guidance skill made of markdown reference material, with no code execution, credentials, persistence, or hidden system access.

Install this if you want a Chinese-language self-reflection and habit-building framework. Do not treat it as therapy, medical advice, or addiction treatment, and be cautious with physically risky suggestions such as cold exposure or with sharing highly sensitive personal details in reflective prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to trigger on many generic self-improvement, habit-building, procrastination, and life-direction queries. That can cause the agent to route users into this framework even when they did not ask for this specific methodology, reducing precision and potentially overriding better-suited or safer skills for mental-health-adjacent requests.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written entirely in Chinese and does not indicate language negotiation or fallback behavior. If invoked for users in other locales, it may produce inaccessible or misunderstood guidance, which is especially problematic here because the content is reflective and psychologically framed, so nuance matters.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal