Back to skill

Security audit

wang-yangming-agent-mind

Security checks across malware telemetry and agentic risk

Overview

This is a text-only philosophy-based agent guidance skill with broad activation and formatting influence, but no hidden code execution, credential access, or destructive behavior.

Install this if you want a Wang Yangming-style reasoning framework to broadly influence agent planning and self-correction. In environments with strict response formats or many auto-activated skills, narrow the activation rules and make the philosophy note optional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation conditions are very broad and cover common agent behaviors like planning, multi-step workflows, ambiguity handling, and error recovery. In a skill system with automatic activation, this can cause the skill to trigger on a large fraction of tasks, unintentionally overriding more specific instructions, affecting routing, or altering safety-relevant decision logic across unrelated contexts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation signals are highly generic—decision-making, planning, ethics, routing, and hallucination avoidance apply to many ordinary agent tasks. This can cause the skill to trigger unnecessarily and inject its behavioral directives into unrelated interactions, increasing the chance of policy drift, unwanted formatting, or interference with system/developer instructions.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
Mandating a prepended philosophy note changes the assistant's output format regardless of user preference or locale. While not directly a code-execution risk, it can cause instruction conflicts, disclosure of internal framing, and reduced compliance with user-requested style or platform response policies.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.