Dopesick

Security checks across malware telemetry and agentic risk

Overview

This is a text-only educational skill about the opioid epidemic with no executable code, credential use, persistence, or data access, though its activation terms are somewhat broad.

Reasonable to install if you want an opioid-epidemic reference skill. Be aware it may activate on general addiction or treatment discussions, and its guidance is educational rather than a substitute for current medical, legal, or emergency advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains very broad terms like 'Addiction', 'treatment', and behavior-based activation such as when a user says they just installed the skill or does not know how to start. This can cause unintended invocation during unrelated health, recovery, legal, or onboarding conversations, leading to scope hijacking and potentially displacing the user's actual intent with opioid-epidemic content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal