Back to skill

Security audit

Gentle Reframe Companion

Security checks across malware telemetry and agentic risk

Overview

This is a text-only emotional reframing skill with no code execution or data access, but it should not be used for acute mental-health crises.

Use this only as a lightweight self-reflection aid for mild everyday distress. Do not rely on it for suicidal thoughts, self-harm, violence risk, severe panic, dissociation, psychosis, or any situation where someone may not be safe; seek emergency, crisis, or qualified mental-health support instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly says it does not handle self-harm, suicide, violence, or crisis situations, but an example invites use during 'anxiety attacks,' which can overlap with acute mental-health crises and impair a user's ability to self-assess safety. This contradiction may cause the agent to provide generic reframing instead of an immediate safety-oriented redirect when the user is in distress.

Intent-Code Divergence

Low
Confidence
82% confidence
Finding
The skill claims to be non-directive and gentle, but several examples prescribe interpretations and actions, including speculative attributions such as guessing a boss's emotional state. In a mental-health-adjacent context, this can reinforce inaccurate narratives, encourage mind-reading, and push users toward advice that is not grounded in verified facts.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation excludes crisis scenarios but does not provide a clear warning, refusal flow, or referral path for unsafe mental-health situations. In practice, a distressed user may still use the skill and receive ordinary reframing instead of urgent guidance to seek immediate human help.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.