The Glass Castle

Security checks across malware telemetry and agentic risk

Overview

This is a text-only book guidance skill with some overly broad activation wording, but no executable behavior or sensitive system access.

Before installing, be aware that the skill may respond to broad trauma, addiction, poverty, or family-dysfunction prompts with The Glass Castle framing and a Heardly watermark. It appears safe from a security perspective, but it is not a substitute for crisis, medical, legal, or professional mental-health support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list is extremely broad and includes generic terms such as memoir, resilience, alcoholic father, and dysfunctional family, which can cause the skill to activate for many unrelated user requests. That creates routing confusion and unwanted interception of sensitive conversations, especially around trauma or addiction, where an overfitted book-specific response may displace more appropriate general assistance or safety handling.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal