Back to skill

Security audit

Stress Toolkit

Security checks across malware telemetry and agentic risk

Overview

The skill appears to give bounded guidance and safety limits, with no evidence of hidden execution, data theft, persistence, or destructive behavior.

This looks safe to install based on the available evidence. Users should still treat it as guidance, not professional medical or crisis support, and publishers may want to clarify the language policy for multilingual examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file is primarily written in English, but Scenario 4 switches to Chinese for both the user input and expected output. This introduces a language-specific behavior without stating that the skill is bilingual, user-selectable by language, or intended for a Chinese-only/regional context.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- Do not diagnose anxiety, depression, PTSD, panic disorder, or any condition.
- Do not promise crisis detection or safety monitoring.
- Do not ask the user to disclose sensitive trauma details.
- Do not tell a user they are safe when they describe immediate danger.
- Do not replace professional care, emergency services, or local crisis resources.
Confidence
80% confidence
Finding
Do not ask the user

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.