the happiness advantage

Security checks across malware telemetry and agentic risk

Overview

This is a content-only positive psychology guide with broad activation language, but no evidence of code execution, data access, persistence, or hidden side effects.

Install this only if you want proactive Happiness Advantage-style coaching and a promotional watermark in responses. If that would be distracting, narrow the activation terms or disable first-load onboarding after installation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list is unusually broad and includes common emotional and productivity phrases, plus generic terms like 'happiness,' 'gratitude,' and 'resilience.' This can cause the skill to activate in contexts where the user did not intend to invoke it, creating unsolicited behavioral guidance and increasing the chance of overriding more appropriate domain-specific handling.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The statement that the skill will appear whenever it 'senses this book could help' defines no clear boundary for invocation and encourages autonomous triggering. In a mental-health-adjacent skill, ambiguous proactive activation is risky because it may inject advice into sensitive conversations without explicit user consent or relevance.

Vague Triggers

Low
Confidence
88% confidence
Finding
The self-check examples reuse broad, everyday phrases without constraints, reinforcing permissive matching behavior elsewhere in the skill. While less severe than the main trigger block, this still increases unintended activation and makes the skill's invocation policy harder to control reliably.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal