Back to skill

Security audit

strong-mindset

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed coaching and report-generation package, but its guidance includes manipulative persuasion themes that users should review before installing.

Review the style guide before installing. The local report generator and bundled references are not the main issue; the main risk is that the skill may apply a forceful coaching persona broadly and may produce advice about concealed intent or persuasive influence without explicit consent and ethics guardrails.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to read `references/style-guide.md`, optionally read multiple files under `references/articles/`, and use `references/generate_report.py` to write a single-file HTML report, which implies file-read and file-write behavior without any declared permissions. Undeclared file capabilities create a trust and containment gap: the host or reviewer cannot accurately assess what resources the skill needs, and broad file access patterns can be abused or misconfigured to read unintended files or write artifacts in unsafe locations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The primary activation signals include very broad states like confusion, rumination, being drained, or asking for advice in a concrete situation, which overlap heavily with ordinary conversation. Over-broad routing increases the chance of unintended invocation, causing the skill to take over unrelated exchanges and potentially trigger downstream file-reading/report-generation behavior when the user did not intend to use this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword trigger list is open-ended and composed of generic motivational or self-help phrases that can appear in many benign contexts, with no scope constraints or exclusions. This makes accidental invocation more likely and can steer the assistant into an unintended persona/workflow, increasing the chance of inappropriate content transformation or unnecessary access to local reference assets.

Ssd 4

Medium
Confidence
95% confidence
Finding
This section explicitly teaches users to hide goals, avoid revealing intent, and embed objectives inside stories. In a coaching skill, that normalizes deceptive persuasion and can be repurposed for social engineering, workplace manipulation, or coercive relationship tactics, making the context more dangerous rather than less.

Ssd 4

Medium
Confidence
94% confidence
Finding
This passage frames support-gaining as making others feel they benefit and operationalizes trust-building and conversational steering as a means to secure compliance. While some persuasion is legitimate, the surrounding 'strong mindset' framing and repeated strategic/social-engineering themes increase the risk that the skill will coach manipulative influence under benign language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.