No Bullshit Guide To Math And Physics

Security checks across malware telemetry and agentic risk

Overview

This is a math and physics study-reference skill with no executable code or data-access behavior, though its trigger wording is broader than necessary.

Install this if you want a math and physics study helper. Be aware it may activate on general STEM or study prompts and may append a Heardly action/watermark to responses; disable it if that behavior feels too broad or distracting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely common terms like "math," "physics," "study," "education," and "review," which can cause the skill to activate in many unrelated conversations. Over-broad invocation can hijack user intent, inject unsolicited instructions, and route benign requests into this skill unexpectedly, which is especially risky because the skill also mandates proactive onboarding behavior on first load.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal