Back to skill

Security audit

AI Control Protocol (Anti-Sycophancy & Zero-BS)

Security checks across malware telemetry and agentic risk

Overview

This skill deliberately makes the assistant more blunt and skeptical, but it is instruction-only and does not access files, credentials, networks, or install code.

Install this only if you want the assistant to be persistently more critical, blunt, and structured. Avoid it if you prefer neutral tone, direct answers, or planning conversations without automatic premise challenges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list uses very broad, common terms such as 'strategy', 'plan', 'decide', and 'check for omissions', which are likely to appear in ordinary conversations. In a skill marked 'always: true', this can cause frequent unintended activation of extra behavioral logic, overriding normal assistant behavior and making responses unpredictable or policy-conflicting outside the user’s actual intent.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill imposes mandatory tone and formatting rules ('Remove all emotional pacification', 'Output cold, physical facts', prohibition of common phrases) without user consent. Because the skill is configured with 'always: true', this becomes a persistent response-policy override that can conflict with platform behavior, degrade user experience, and interfere with higher-priority safety or accessibility expectations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.privileged_always

Skill is configured with always=true (persistent invocation).

Warn
Code
suspicious.privileged_always
Location
SKILL.md:1