Crime And Punishment

Security checks across malware telemetry and agentic risk

Overview

This is a text-only literature skill, but one section gives a guilty user practical advice for handling an investigation in a way that conflicts with the skill’s stated confession-and-accountability purpose.

Before installing, read the Porfiry Protocol section carefully. The skill is text-only and does not appear to access your files or credentials, but it includes advice that could be unsafe if you are actually under investigation or considering whether to disclose wrongdoing. Use it for literary and ethical reflection, not for avoiding accountability; for legal, workplace, or safety-sensitive situations, consult a qualified professional and preserve relevant evidence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
This section gives actionable advice to a user who is explicitly described as guilty and under investigation, including how to avoid increasing suspicion and how silence can be strategically safest. Even in a literary or reflective skill, packaging this as a reusable 'protocol' operationalizes anti-investigative behavior and can help culpable users evade accountability or obstruct fact-finding.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is broad enough to match common self-reflective or onboarding phrases, which can cause the skill to activate outside clear user intent. Because the skill delivers strong moral and confession-oriented framing, unintended invocation may steer users into sensitive guidance they did not explicitly request, creating consent and relevance risks.

Vague Triggers

Low
Confidence
85% confidence
Finding
The sample phrase "Map this book to my life" is broad and conversational, and if used as a trigger pattern it may overlap with ordinary discussion of books or personal situations. On its own this is lower risk than the main trigger block, but it still contributes to accidental routing into a psychologically heavy framework.

Ssd 4

High
Confidence
97% confidence
Finding
The text presents a step-by-step technique for a guilty person facing investigation, including instructions not to overperform innocence, to let the investigator do the work, and that silence is safest. This is dangerous because it converts fictional analysis into practical evasion guidance, lowering the barrier for wrongdoers to resist detection while maintaining plausible deniability under the skill's redemptive framing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal