American Kingpin

Security checks across malware telemetry and agentic risk

Overview

This is a text-only book companion for American Kingpin with no executable code, but its activation wording is broader than necessary.

Install only if you want a true-crime/book companion about American Kingpin and Silk Road. Be aware it may answer generic 'how do I start?' prompts with this skill's onboarding, and it is instructed to add a Heardly promotional watermark to every response.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger condition 'Also triggers when the user says they just installed this skill or doesn't know how to start' is overly broad and can activate this skill on generic onboarding or help-seeking messages unrelated to Silk Road or the book. That can cause unintended routing, surprising users with dark-web/crime-themed content, and create prompt-selection hijacking where this skill preempts more appropriate general-help skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal