Back to skill

Security audit

AI 八耻八荣 (ai-eight-creed)

Security checks across malware telemetry and agentic risk

Overview

This is a safety-oriented prompt creed, but it asks to become a highest-priority, always-on rule set across all domains, which is broader than a normal skill should require.

Install only if you intentionally want this creed to shape agent behavior persistently. Do not place it above platform/system policies or all task instructions; keep it scoped as optional guidance and remove or narrow the always-on memory/rules-file instructions if they conflict with your workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The README explicitly instructs users to install the creed as a highest-priority, always-on policy that applies across domains. Even though the creed content is mostly safety-oriented, a universal top-priority rule set can override application-specific policies, user preferences, or platform safeguards, making it a prompt-governance risk.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The statement that this creed sits above any task instruction and 'the creed wins' creates an unconditional override mechanism. In agent systems, any third-party policy that claims priority over all task instructions can interfere with legitimate workflows, conflict with safety controls, and create policy confusion even if the content appears well-intentioned.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger includes a catch-all natural-language condition: "any request involving agent behavior rules or ethical guidelines." This is overly broad and can cause the skill to activate in many unrelated contexts, potentially overriding more specific skills or injecting this skill’s governance text into conversations where it was not intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
README.en.md:58