Back to skill

Security audit

Olympic Alert

Security checks across malware telemetry and agentic risk

Overview

This is a local Olympic event reminder that uses disclosed schedule and state files, with no evidence of hidden network access, credential use, or unrelated data handling.

Install this if you want Olympic-related trigger words or a heartbeat to run a local reminder checker. Review the add/remove behavior before using it, because those commands edit the local events.json schedule and removal is based on name-pattern matching.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
75% confidence
Finding
The trigger set includes broad terms such as `올림픽`, `Olympic`, and `밀라노`, which can match many ordinary conversations unrelated to alert management. Overbroad triggers can cause unintended invocation, leading to confusing behavior, unnecessary file operations, or accidental modification/listing flows in contexts where the user did not intend to use this skill.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.