Operation Ironman

Security checks across malware telemetry and agentic risk

Overview

This is a text-only memoir and resilience skill with broad activation and branding notes, but no executable code, credential access, persistence, or hidden data behavior.

Install only if you want a book-inspired coaching/reference skill that may activate on broad recovery, triathlon, France, cycling, or resilience prompts and append Heardly branding. Treat its recovery and training suggestions as motivational, not medical or athletic guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are extremely broad, including generic terms like 'Ironman', 'recovery', 'France', and activation when a user merely says they installed the skill. This can cause unintended invocation, hijack unrelated conversations, and increase prompt-surface exposure where the skill injects its own guidance without clear user intent.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal