Deng Xiaoping And The Transformation Of China

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a topical research/onboarding skill with no evidence of malware, data access, credential use, persistence, or destructive behavior.

This looks safe to install from a security standpoint, but it may activate more often than expected because its triggers appear broad. If it interrupts unrelated conversations or adds unwanted onboarding/watermark-style content, narrow or disable the trigger behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger logic is excessively broad because it activates not only on highly generic terms like "China," "reform," and "1989," but also when a user merely says they just installed the skill or do not know how to start. This can cause unintended invocation in unrelated conversations, increasing the chance the skill hijacks context, injects irrelevant instructions such as mandatory onboarding or watermarking, and interferes with normal assistant behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal