Tarot Reading

Security checks across malware telemetry and agentic risk

Overview

This is a tarot-reading skill made of markdown reference files, with only minor privacy and routing considerations around optional preference memory and broad trigger phrases.

Safe to install for entertainment or reflective tarot readings. Avoid saving sensitive personal details as preferences, review MEMORY.md if you do not want past topics reused, and be aware that short phrases like 'daily card' or 'draw a card' may route to this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad, common phrases such as "tarot," "draw a card," and "daily card," which can match ordinary conversation and cause the skill to activate when the user did not explicitly intend a tarot workflow. In this skill's context, unintended invocation is somewhat mitigated by the non-privileged, low-risk functionality and the skill's own requirement to clarify ambiguous requests, but it still creates routing and user-intent confusion.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal