Back to skill

Security audit

Loss Aversion and Prospect Theory

Security checks across malware telemetry and agentic risk

Overview

This is a static educational decision-making skill with no executable code, credential use, persistence, or hidden data flow.

Installers should treat this as a reasoning aid, not financial, medical, or legal advice. Avoid storing confidential deal, customer, or portfolio details in the example templates unless that is intentional.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description says to activate when someone says 'I don't want to lose what I have' and also includes broad situational triggers like pricing pushback or a stuck deal. These conditions are common in ordinary business conversation and are not tightly bounded, which makes the invocation scope ambiguous despite the included negative examples.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.