Back to skill

Security audit

Travel Volunteer Ethics Evaluator

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk descriptive travel aid for evaluating volunteer tourism ethics, with no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Reasonable to install if you want informational help vetting volunteer tourism programs. Treat its advice as a planning framework, verify organizations independently, and be aware that some generic travel prompts may route here even when you intended broader travel planning.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger section uses broad phrases such as 'community if applicable' and generic volunteer/ethics wording that could cause accidental invocation outside the intended scope. Overbroad activation can route unrelated user conversations into this skill, creating prompt-routing confusion, misleading advice, or unintended exposure of user context to an irrelevant skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example prompts include everyday travel-planning phrasing like 'help me with ... for my trip' and 'provide ... framework for travel planning,' which is too generic for reliable dispatch. In a multi-skill environment, this can cause inappropriate activation, lower trust in routing, and produce irrelevant recommendations when users are asking for general travel help rather than ethics evaluation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.