Back to skill

Security audit

Focus Toolkit

Security checks across malware telemetry and agentic risk

Overview

This focus skill does what it advertises: timers, reminders, generated sound files, and local focus reports, with no evidence of hidden data access or exfiltration.

Install only if you want a skill that can create reminders and keep local pomodoro history. Be explicit about reminder times and recurrence, and review/remove any recurring reminders through your environment's normal reminder or cron controls if you no longer want them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises broad natural-language trigger phrases like '开始专注,放段雨声,30 分钟后叫我' and '每天早上9点提醒我站会' without defining clear activation boundaries, confirmation requirements, or exclusions. In a multi-skill or agentic environment, this can cause overbroad invocation and unintended execution of actions such as scheduling reminders, starting timers, or generating audio when the user did not intend to invoke this specific skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.