Ministry Weekly

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent church communications helper with disclosed local persistence and user-confirmed Telegram posting.

Before installing, be aware that the skill will keep church profile and weekly ministry context locally so it can reuse it later. Review any generated bulletin, social, email, or Telegram content before publishing, especially scripture interpretation, public announcements, and congregation-specific details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README explicitly says the skill also responds to casual phrasing like 'help me with Sunday's stuff' or 'I need content for this week' in a church context, which broadens activation beyond the stricter weekly-production triggers described elsewhere. In an agent setting, overly broad trigger language can cause unintended invocation on ambiguous church-related conversations, leading to unnecessary data persistence, mistaken content generation, or accidental progression toward downstream actions like Telegram delivery prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal