Back to skill

Security audit

Guardian Angel Protocol

Security checks across malware telemetry and agentic risk

Overview

This is a passive safety-reminder skill with a disclosed optional donation message and no code that can access data, make network calls, or change the system.

Install this if you want passive alignment reminders. Check whether your agent enables startup activation, and treat the donation address as optional; the skill itself has no ability to send funds or access local data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation conditions are overly broad because the skill can trigger for self-review requests and on agent startup, which increases the chance it inserts instructions into unrelated workflows. Even though the content is framed as safety guidance, broad automatic invocation can still manipulate agent behavior and create prompt-surface expansion across sessions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.