The Monk Who Sold His Ferrari

Security checks across malware telemetry and agentic risk

Overview

This is a text-only self-help/book companion skill with broad activation wording but no executable code, credential use, persistence, or data access.

Install only if you want a book-specific self-help assistant. Be aware it may activate on broad purpose, meaning, positivity, discipline, or ritual-related prompts, and its advice reflects the book's worldview rather than neutral or clinical guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list includes broad, common phrases such as 'Life purpose,' 'Find meaning,' 'Positive thinking,' 'Daily rituals,' and even activates when a user says they just installed the skill or does not know how to start. These terms can appear in many unrelated conversations, causing accidental invocation and unwanted steering toward this skill's worldview or recommendations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal