Born To Run

Security checks across malware telemetry and agentic risk

Overview

This is a text-only running advice skill with no executable or data-access behavior, but its barefoot and injury guidance should be treated cautiously.

Install only if you want Born to Run-style running guidance. Treat barefoot/minimalist and injury advice as general education, transition gradually, stop if pain worsens, and consult a qualified clinician or running professional for persistent pain, prior injuries, diabetes/neuropathy, balance issues, or other medical concerns.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill declares very broad trigger phrases such as common running pain, shoes, form, and general book/topic mentions, which can cause the skill to activate in many ordinary fitness conversations without clear user intent to invoke this specific skill. That increases the chance of unwanted steering into the skill’s prescriptive guidance, including health-related recommendations, when the user may have intended a generic discussion or a different tool.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The instruction to trigger when a user says they just installed the skill or 'doesn't know how to start' is ambiguous and encourages proactive activation without a precise scope check. This can lead the assistant to inject the skill unprompted into unrelated onboarding or help-seeking contexts, overriding conversational relevance and potentially presenting strong health/fitness claims without sufficient user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This content gives prescriptive exercise, gait, cadence, and homemade fueling advice as generally applicable guidance without screening for injuries, medical conditions, fitness level, allergies, or contraindications. In this skill’s context, users are explicitly likely to ask about pain, injuries, barefoot transition, and ultra-endurance, so presenting advice like barefoot jogging, targeting 180 steps per minute, and consuming a specific drink without safety qualifiers could contribute to worsening musculoskeletal injury or inappropriate self-treatment.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The content gives injury-related running advice and explicitly recommends barefoot running as a corrective step for people with shin splints, runner's knee, plantar fasciitis, and IT band syndrome without any safety caveats, screening criteria, or referral to a qualified clinician. In a skill designed to be triggered by users already in pain or asking how to run without injury, this can lead users to self-treat incorrectly, potentially worsening overuse injuries or delaying appropriate medical evaluation.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal