Across That Bridge

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a content-focused guidance skill with one routing concern, but no evidence of harmful access, persistence, credential use, or destructive behavior.

Installers should expect this skill to provide thematic guidance around John Lewis and nonviolence. The main caveat is that broad trigger words like change, peace, faith, justice, and leadership may make it appear more often than intended; disable or narrow it if it interferes with unrelated conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes extremely common terms such as "change," "peace," "faith," "justice," and "leadership," plus a rule to trigger when a user says they just installed the skill or do not know how to start. This can cause the skill to activate in many unrelated conversations, leading to unintended instruction injection into user sessions, reduced routing integrity, and possible interference with higher-priority or more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal