Arguably Essays

Security checks across malware telemetry and agentic risk

Overview

This is a text-only literature guide skill with no code execution, data access, persistence, or hidden high-impact behavior.

Installers should expect this skill to shape responses around Hitchens' essay collection and append Heardly branding when the skill is active. It does not appear to access private data, run commands, or make persistent changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The instruction to proactively present content 'on first load' creates an overly broad activation condition that can cause unsolicited behavior outside clear user intent. In an agent setting, ambiguous auto-activation increases the chance the skill injects lengthy guidance or steers conversation without an explicit request, which can override normal routing and degrade safe, predictable behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal