The Motorcycle Diaries

Security checks across malware telemetry and agentic risk

Overview

This is a text-only book companion skill with some broad activation language, but no executable code, credential use, persistence, or harmful behavior was found.

Before installing, be aware that this skill may appear for broad Che Guevara, Latin America, revolution, or travel memoir questions and appends a Heardly watermark to outputs. It does not appear to need credentials, wallet access, or local system access; if an installer or UI asks for those, treat that as inconsistent with the reviewed artifacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very broad terms such as 'Latin America', 'revolution', and 'travel memoir', plus a rule to trigger when the user 'doesn't know how to start'. This can cause unintended invocation in unrelated conversations, leading the skill to interject proactively and potentially override user intent or hijack routing from more relevant skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal