Lorem Toolkit

Security checks across malware telemetry and agentic risk

Overview

This appears to be a low-impact content-generation skill with only minor routing breadth concerns.

This skill looks safe to install for generating placeholder or test content. Be aware it may activate in generic fake-data or multilingual contexts, so review its trigger wording if accidental invocation would be disruptive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description includes a very broad trigger condition for requests involving placeholder text, fake data, or test content, which can cause the skill to activate in many generic contexts. Overbroad triggering increases the chance of unintended invocation, response hijacking, or routing user requests to a lower-trust skill when the user did not explicitly ask for this toolkit.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
The manifest mixes Chinese trigger text into the description without indicating that the skill is intended for Chinese-language routing or that multilingual matching is deliberate. This can broaden activation unexpectedly across languages and cause the skill to be selected for users who did not opt into that locale, increasing misrouting risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal