Message in a Bottle

Security checks across malware telemetry and agentic risk

Overview

This skill only returns a random prewritten inspirational message and does not request sensitive access or perform risky actions.

This is low risk to install. Be aware it may trigger on broad requests for inspiration or a random message; install it if that behavior is acceptable, or narrow the trigger wording if you want it to activate only for explicit message-in-a-bottle requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description includes broad phrases such as 'random message' and 'needs inspiration/wisdom', which are common in normal conversation and can cause the skill to activate when the user did not explicitly request it. In this skill, the consequence is limited because the action only returns a pre-written message, but unintended invocation can still confuse users and interfere with routing to more appropriate skills.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal