Recycle

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight recycling guidance skill with no code, install steps, credential use, or hidden device/account access.

Reasonable to install as an advisory recycling helper. For real pickup appointments, discounts, policies, or carbon-account actions, verify details through official providers and avoid sharing unnecessary personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are overly generic and include placeholders like '具体场景任务' and broad requests about '核心功能' and '最新玩法/优惠信息', which can match ordinary user queries rather than clearly skill-scoped invocations. This increases the chance of unintended routing or activation, causing the skill to intercept unrelated requests and potentially expose users to incorrect actions, unnecessary data collection flows, or confusing task execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal