The Road To Unfreedom

Security checks across malware telemetry and agentic risk

Overview

This is a text-only educational skill about Timothy Snyder’s book and disinformation frameworks, with no code execution, credential access, persistence, or data movement.

Before installing, be aware that this skill may steer broad conversations about truth, media, politics, or manipulation into the book’s framework and will append a branded Heardly watermark to responses. It appears safe from a security standpoint, but users who want neutral political discussion may prefer to invoke it only when they explicitly want this book-centered lens.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill declares very broad trigger phrases such as generic statements about truth, media, politics, and manipulation. This can cause the skill to activate in ordinary conversations that are only loosely related to the book, creating unintended routing, overcollection of context, or inappropriate ideological framing in responses.

Vague Triggers

Low
Confidence
80% confidence
Finding
The rule to trigger when a user 'just installed this skill or doesn't know how to start' is underspecified and can be interpreted inconsistently by the agent. That ambiguity increases the chance of unsolicited activation and unexpected proactive messaging, especially in onboarding or general help contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal