The Mountain Is You

Security checks across malware telemetry and agentic risk

Overview

This appears to be a non-executable self-help/book-framework skill, but users should treat it as reflective coaching rather than mental health care.

Install only if you want a book-based reflective coaching framework. Do not use it as therapy or crisis support, and avoid letting it steer conversations about self-harm, abuse, severe trauma, or overwhelming distress without qualified human support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad and overlaps with common mental-health and emotional-support phrasing, so the skill may activate for users seeking general support rather than a book-specific framework. That can cause inappropriate routing, over-application of this skill's worldview, and reduced likelihood that safer or more suitable handling is used for sensitive situations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Telling the assistant to appear whenever it 'senses this book could help' creates an open-ended activation rule that invites subjective over-triggering. In a self-help skill dealing with vulnerable emotional states, this increases the chance of unsolicited intervention and misclassification of ordinary or high-risk support conversations into a branded framework.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section gives quasi-therapeutic guidance for intrusive thoughts, trauma responses, grief, and chronic fear without any safety framing, crisis boundaries, or recommendation to seek qualified support when symptoms are severe. In a self-help skill explicitly triggered by users who feel stuck, self-destructive, or emotionally overwhelmed, users may over-rely on simplistic interpretations of distress and delay appropriate care.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The 'Letting Go Protocol' directs users through emotionally intense grief processing and encourages deep emotional release without guardrails for destabilization, retraumatization, or situations involving acute depression, trauma, or self-harm risk. Because the skill is positioned as an executable toolkit for emotionally vulnerable users, this can push users into high-intensity self-guided processing beyond safe scope.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The file presents inner-child visualization and future-self practices as core methodology without any safety framing, limitations, or guidance on when such reflective exercises may be inappropriate. In a skill explicitly triggered by users describing self-sabotage, emotional distress, abandonment, trauma, and feeling stuck, this can lead the agent to provide quasi-therapeutic guidance to vulnerable users without guardrails, potentially worsening rumination, distress, or false self-interpretation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal