Back to skill

Security audit

Musk First Principles

Security checks across malware telemetry and agentic risk

Overview

This appears to be a text-only strategy/persona skill with no evidence of code execution, data access, persistence, or hidden behavior.

Install this if you want a Chinese-first Musk/first-principles decision framework. Be aware it may activate on broad prompts about cost reduction, hard decisions, or similar strategy topics, so explicitly ask for another style or language when you do not want that framing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation phrases are very broad natural-language prompts such as cost reduction, hard decisions, or asking how Musk would think. These overlap with ordinary user conversation, so the skill may be invoked unintentionally and steer responses into a specific persona/framework without explicit user consent, causing prompt routing errors and inappropriate advice in unrelated contexts.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
Declaring Chinese as the primary language without user choice can override the user's preferred language and reduce comprehension or safe use, especially for nuanced strategic or technical advice. This is a quality and safety issue because language mismatch can cause misunderstanding, but it does not create direct code-execution or data-exfiltration risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.