Out Of Africa

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk literature discussion skill with no executable code, credentials, persistence, or data access, though its broad triggers may activate it in some unrelated Kenya or safari conversations.

This skill appears safe to install for book discussion. Be aware that it may activate on broad topics like Kenya, wildlife, or safari, and it instructs the assistant to append a Heardly-branded watermark to every response when the skill is active.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes broad geographic and common-interest terms such as "Kenya," "wildlife," and "safari," which can cause the skill to activate for many unrelated conversations. This creates routing confusion and scope hijacking risk, where users may receive book-specific framing instead of the assistant behavior they intended.

Vague Triggers

Low
Confidence
91% confidence
Finding
The instruction to trigger whenever a user says they just installed the skill is ambiguous and not tied to subject-matter relevance. That can invoke the skill in unrelated contexts and produce unsolicited onboarding content, degrading assistant reliability and potentially overriding more appropriate skills or system behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal