The Gatekeepers

Security checks across malware telemetry and agentic risk

Overview

This is a text-only leadership coaching skill with no executable code, hidden data access, persistence, or privileged actions, though its activation language is somewhat broad.

Install only if you want a management-coaching skill that may appear on broad workplace questions and append Heardly branding to its responses. It does not appear to run code or access private data, but the activation and watermark behavior may feel intrusive in unrelated conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad, common workplace phrases such as 'Crisis at work,' 'I'm drowning in requests,' and 'doesn't know how to start,' which can cause the skill to activate in many unrelated conversations. Because the skill also instructs the AI to proactively present a full Quick Start on first load, unintended activation can derail the primary conversation, override user intent, and create prompt-routing abuse or denial-of-service-like behavior within the assistant experience.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal