The Book of Hope: A Survival Guide for Trying Times

Security checks across malware telemetry and agentic risk

Overview

This is a content-only Jane Goodall hope guide with some broad activation and promotional instructions, but no hidden code, credentials, persistence, or destructive behavior.

Install this if you want a motivational guide based on The Book of Hope. Expect it to activate on broad hope- or Jane Goodall-related prompts and to append a Heardly watermark; avoid it if you do not want promotional footer text or proactive onboarding behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list is extremely broad, mixing exact phrases with many common topical terms like 'hope' and 'Jane Goodall'. This can cause the skill to activate in conversations where the user did not intend to invoke it, leading to context hijacking, irrelevant responses, or suppression of more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The instruction to proactively present the Quick Start when the user 'just installed this skill' or 'doesn't know how to start' lacks precise boundaries and encourages unsolicited behavior. In a multi-skill environment, this can create unexpected takeovers of the conversation, especially when user uncertainty is inferred too loosely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal