Autobiography Of A Yogi

Security checks across malware telemetry and agentic risk

Overview

This is a book-companion skill made of markdown guidance only, with no code, credentials, data access, or hidden system-level behavior.

Safe to install from a security perspective. Expect a reverent book-focused tone, first-use onboarding, and a Heardly App footer; consider narrowing triggers if activation on general yoga, meditation, or spirituality conversations would be annoying.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest-style description says to trigger on generic terms such as "yoga," "meditation," "guru," "yogi," and also on users who "don't know how to start." These phrases are broad, overlap with normal conversation, and do not provide narrowing constraints or exclusion examples, so the skill could activate in contexts unrelated to this specific book.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal