Letting Go

Security checks across malware telemetry and agentic risk

Overview

This is a text-only self-help skill with no code or data access, but its emotional-crisis guidance is broad and lacks clear safety boundaries.

Review this carefully before installing if you do not want unsolicited spiritual self-help in emotional conversations. Treat it as reflective book-based guidance, not therapy, medical advice, or crisis support; in self-harm, abuse, psychosis, overwhelming distress, or inability to function, use professional or emergency resources instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is extremely broad and includes common emotional terms such as fear, anger, grief, forgiveness, and acceptance, making accidental or inappropriate invocation likely in many unrelated conversations. In a mental-health-adjacent skill, over-triggering is dangerous because it can insert prescriptive spiritual guidance into sensitive situations without clear user intent, potentially displacing safer, more appropriate support.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The statement that the skill will appear whenever it 'sense[s] this book could help' creates an undefined, subjective activation rule that encourages the assistant to self-invoke based on weak inference rather than explicit consent. In practice, this can cause the skill to surface in emotionally vulnerable moments where unsolicited spiritual advice may be inappropriate or harmful.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill presents real-time guidance for anxiety, anger, grief, and emotional crisis-like situations without warnings, scope limits, or direction to professional or emergency resources. Because the content frames itself as an executable toolkit and includes advice for grief and intense distress, users may over-rely on it as a substitute for mental health care, especially during acute vulnerability.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file gives broad 'emotional crisis' guidance such as 'don't resist,' 'don't act,' and 'surrender repeatedly' without any warning that this framework is not sufficient for severe mental-health situations. In a skill explicitly triggered by users in grief, anxiety, betrayal, or crisis, this can discourage seeking urgent professional or emergency support and may be unsafe for users with suicidality, psychosis, severe depression, panic, trauma, or inability to care for themselves.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal