Becoming Supernatural

Security checks across malware telemetry and agentic risk

Overview

This is a content-only meditation/self-help skill, but it gives strong medical and trauma-healing guidance that could mislead vulnerable users without adequate safety boundaries.

Review carefully before installing. This skill is content-only and does not appear to access your files or run code, but it should be treated as spiritual/self-help material, not medical or mental-health guidance. Do not use it to replace clinicians, medication, addiction treatment, trauma therapy, emergency care, or evidence-based treatment plans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
This section presents meditation and consciousness practices as a way to heal chronic pain, cancer, Parkinson's disease, and other serious conditions, which can encourage users to rely on unproven methods instead of appropriate medical care. In a user-facing agent skill, these claims are especially dangerous because they are framed as actionable playbooks and reinforced with anecdotal remission stories that may be perceived as medical guidance.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The trauma section gives step-by-step recovery instructions in a way that can substitute for trauma-informed mental health treatment, despite trauma being a condition that may involve PTSD, dissociation, suicidality, or other high-risk symptoms. Because the skill presents these practices as sufficient healing methods and recommends intensive retreats, vulnerable users may delay or avoid professional care.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes highly generic terms such as 'meditation' and broad life-problem phrases, which can cause the skill to activate in many unrelated contexts. This creates unintended routing risk and may surface medically themed or pseudoscientific guidance to users who did not explicitly ask for it, increasing the chance of harmful or misleading advice being injected into normal conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The statement 'I'll show up whenever I sense this book could help' defines activation in subjective, ambiguous terms rather than deterministic criteria. That ambiguity encourages overbroad invocation and makes it more likely the skill will appear in sensitive contexts, including health or trauma discussions, without clear user consent.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly markets itself for healing chronic illness, pain, trauma, and addiction-related behavior change while presenting speculative concepts like 'quantum healing' and 'epigenetics' as a toolkit, but it provides no disclaimer that this is not medical or mental-health advice. In this context, users in vulnerable states may interpret the guidance as therapeutic or curative, delay appropriate care, or substitute unvalidated practices for professional treatment.

Missing User Warnings

High
Confidence
99% confidence
Finding
The expected output for an autoimmune condition tells the user the diagnosis is 'not a life sentence,' instructs them to enter a state of wholeness, use energy-center practices, and rely on case studies of 'incurable' conditions healing, without warning them to maintain evidence-based medical care. For a user with a serious disease, this can reinforce false hope, encourage medical nonadherence, and promote unsupported health claims in place of appropriate treatment.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The useCase text is broad and mixes multiple sensitive health-related outcomes, including healing chronic conditions and manifesting a new reality, without clear activation boundaries. In an agent-routing context, this can cause the skill to trigger for general wellness, medical, or mental-health queries and present speculative or non-evidence-based guidance where users may need clinically grounded support.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The text presents meditation-induced altered states and spontaneous healing claims as factual outcomes without any caution, limits, or advice to seek professional medical care. In this skill’s context, users are explicitly likely to be seeking help for chronic illness, pain, trauma, or addiction, which increases the risk that vulnerable users may substitute these practices for evidence-based treatment or push themselves into distressing practices based on overstated claims.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This content discusses trauma, chronic illness, diagnosis identity, and healing in a directive way without any disclaimer that it is not medical or mental-health advice and may be distressing. In this skill’s context, the risk is elevated because users may already be vulnerable, seeking relief from illness, pain, or trauma, and could interpret the guidance as authoritative advice to deprioritize evidence-based care or feel blamed for their condition.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file provides medical and addiction-related guidance without warnings, contraindications, or encouragement to seek professional care, which increases the chance that users will self-manage serious conditions unsafely. In an interactive skill context, omission of safety boundaries can make the agent appear to endorse these practices as adequate care.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The content makes strong health claims that serious diseases, neurological disorders, addiction, and trauma can improve or resolve through meditation, energy work, or shifts in consciousness. Such claims can materially mislead users, especially those who are desperate or medically vulnerable, into abandoning evidence-based treatment or developing false expectations of cure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal