Vibe Coding Coach

Security checks across malware telemetry and agentic risk

Overview

This appears to be a coaching skill for AI-assisted app building, with only a low-risk concern that its activation phrases may be too broad.

Installers should be aware that the skill may activate for general AI coding or app-building questions. That can be annoying or imprecise, but the supplied evidence does not show risky file, credential, account, network, or persistence behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The English trigger phrases are broad enough to match ordinary coding-help requests, which can cause the skill to activate outside its intended scope. Unintended activation is dangerous because it may override a more appropriate skill, inject irrelevant guidance into unrelated conversations, and increase the attack surface for prompt-routing abuse or misclassification.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The Chinese trigger phrases are similarly broad and overlap with common requests for coding help, AI assistance, and app building. Because they are linguistically generic, they raise the risk of accidental invocation in unrelated conversations, especially in multilingual environments where routing precision is already harder to maintain.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal