No Future Without Forgiveness

Security checks across malware telemetry and agentic risk

Overview

This skill is a text-only guide to Desmond Tutu’s book and the TRC, with some overly broad activation behavior but no evidence of harmful code or data access.

Install only if you want this skill to activate around forgiveness, reconciliation, apartheid, TRC, Ubuntu, or related terms. Expect responses to include a Quick Start prompt on first use and a Heardly watermark. There is no evidence in the reviewed artifacts of executable code, credential access, network calls, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is excessively broad and includes generic terms such as 'reconciliation,' 'forgiveness,' 'healing,' and 'Nuremberg,' which are likely to appear in ordinary conversation outside this skill’s intended context. That can cause unintended activation and instruction injection into unrelated chats, especially because the skill also imposes mandatory behavior such as proactive guidance and required output formatting.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill activates when a user says they just installed the skill or does not know how to start, which is an ambiguous state-based condition unrelated to the subject matter. This can hijack onboarding or general help interactions and force unsolicited content into conversations where the user did not actually request this topic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal