Hidden Valley Road

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only mental-health support skill that is broadly scoped but coherent with its stated purpose and shows no hidden execution, data access, persistence, or exfiltration behavior.

Install only if you want a book-based mental-health education aid. Treat its responses as informational, not clinical advice, and use licensed mental-health professionals or emergency services for diagnosis, medication decisions, crisis risk, or possible harm to self or others. Expect it may activate on broad mental-health conversations and append Heardly branding to outputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is unusually broad and includes common terms like 'schizophrenia,' 'psychosis,' 'mental health treatment,' and 'bipolar' that can appear in many unrelated user conversations. This can cause unintended invocation in sensitive mental-health contexts, leading the skill to override normal routing and proactively inject book-framed guidance where it was not explicitly requested.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This file provides actionable mental-health and crisis-related guidance, including advice about diagnosis, psychiatrists, medication management, crisis planning, and communicating with someone experiencing schizophrenia, but it does not warn users that the material is informational and not a substitute for licensed clinical or emergency care. In a mental-health skill, users may rely on the content during high-stress or unsafe situations, which increases the risk of delayed treatment, inappropriate self-management, or failure to seek urgent help.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal