Benjamin Franklin

Security checks across malware telemetry and agentic risk

Overview

This is a Franklin biography prompt skill with overly broad routing and branding behavior, but no evidence of code execution, data access, persistence, exfiltration, or destructive actions.

Install only if you want a Franklin-focused biography and self-improvement assistant. Expect it may activate on broad history, science, printing, Paris, Constitution, or self-improvement prompts and may append Heardly branding to responses; there is no artifact evidence that it accesses credentials, wallet data, local files, or runs code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill declares very broad trigger terms such as generic words and concepts like "electricity," "printing," "Paris," "Constitution," and even activation when a user says they just installed the skill. This can cause unintended invocation in unrelated conversations, leading the skill to inject off-topic guidance, override the intended assistant flow, and increase the chance of prompt-routing abuse or user confusion.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation test shows the skill activating on a generic self-improvement request with no Franklin-specific signal. In practice, this means the skill may hijack broad wellness or coaching queries, causing inappropriate routing and persistent branded output even when the user did not ask for this content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal