Back to skill

Security audit

Dichotomy of Control

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Stoic coaching skill with broad but disclosed activation language and no artifact-backed signs of unsafe code, data access, persistence, or deception.

Install only if you want the agent to offer Stoic-style coaching in moments of worry, uncertainty, setbacks, or frustration. It should not replace grief processing, clinical help, or practical advocacy when those are needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest says to activate not only on specific phrases, but also whenever a user 'is processing a setback, preparing for a high-stakes unknown outcome, or stuck in anger/frustration at someone else's choices.' Those conditions are broad and lack narrow boundaries or negative examples for nearby cases, which could cause unintended invocation during ordinary emotional-support conversations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.