Back to skill

Security audit

Digital Twin

Security checks across malware telemetry and agentic risk

Overview

This skill is openly designed to build an installable personality clone from a real person's private communications, which needs careful review before use.

Install only if you are creating a profile for yourself or for someone who has explicitly authorized this use. Review which connected sources the agent can access, limit the sources and sample volume, avoid private or sensitive channels unless truly necessary, and do not use the generated persona to mislead others into believing the real person wrote or approved a message.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill operationalizes collection and analysis of a real person's communications to generate an impersonation-capable personality clone, but the warning language is not proportionate to the sensitivity of that activity. Although it mentions consent and privacy later, it does not prominently foreground risks like impersonation, misuse, reputational harm, or unauthorized profiling before encouraging data retrieval from connected sources.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The generated skill is instructed to trigger on broad phrases such as 'respond as {name}' and 'be {name}', which can overlap with normal conversational requests and cause unintended persona activation. In a personality-cloning context, accidental invocation increases the chance of unauthorized impersonation, misleading outputs, and use of derived behavioral data outside the user's intended scope.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger language includes broad catch-all phrases like "any similar instruction," which can cause the persona to activate in ambiguous contexts the user did not clearly intend. In a personality-cloning skill, unintended activation is especially risky because it can silently steer responses into impersonation mode, affecting tone, decisions, and safety behavior across unrelated tasks.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Persistent activation for "ALL responses in the session" without strong constraints creates an overbroad behavioral override that can hijack subsequent interactions beyond the original request. In this skill, that means the model may continue impersonating a real person across unrelated prompts, increasing the chance of misleading outputs, policy bypass pressure, and loss of user control over agent behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This file explicitly instructs the system to capture a person's linguistic fingerprint so generated messages sound like they wrote or said them, but it provides no consent, authorization, or anti-impersonation safeguards. In the context of a digital-twin skill designed to clone named individuals across user-connected communications, that omission materially increases the risk of deceptive impersonation, social engineering, reputational harm, and misuse at scale.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file explicitly instructs the agent to infer sensitive psychometric traits, conflict style, risk tolerance, and emotional disposition from a person's communications, but it provides no warning, consent gate, or limitation on how such inferences should be used. In the context of a digital-twin skill that clones a real named person, this increases the risk of privacy-invasive profiling, mischaracterization, and downstream misuse in impersonation, manipulation, or employment-related judgments.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This content operationalizes creation of a convincing personality clone from a real person's communications and explicitly instructs audience-specific behavioral mimicry, but provides no safeguards around consent, lawful basis, impersonation risk, or privacy-sensitive handling of source material. In this skill context, the omission is dangerous because the whole purpose is high-fidelity emulation of a named individual, which can enable deception, social engineering, reputational harm, and misuse of personal communications data.

Ssd 3

High
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to pull a target person's emails, chats, transcripts, and documents from existing connectors and analyze them to model speech, judgment, and behavior. Even without requesting credentials itself, this creates a privacy and data-exposure path because sensitive communications are being aggregated, transformed, and repurposed into an impersonation artifact that can outlive the original access context.

Ssd 4

High
Confidence
91% confidence
Finding
The workflow breaks harmful behavior into seemingly reasonable steps—confirm consent, retrieve communications, isolate contributions, profile across multiple dimensions, and package the result as an installable clone—which can normalize and obscure the cumulative privacy and impersonation risk. This staged design materially increases danger because it systematizes extraction from multiple private sources into a reusable behavioral replica rather than a one-off analysis.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
Return to normal Claude behavior after unless instructed otherwise.

### Persistent Mode
When this skill is set as the default personality or the user says "always respond as {name}",
keep this skill active for ALL responses in the session. Every message goes through the full
7-step pipeline.
Confidence
90% confidence
Finding
always respond

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.