Think Like A Monk

Security checks across malware telemetry and agentic risk

Overview

This is a self-help guidance skill with broad activation wording, but it contains only markdown/json content and no hidden code, credential access, persistence, or data-moving behavior.

Install only if you want a book-based self-help assistant that may respond to general mindfulness, purpose, routine, and growth topics. Treat its advice as reflective guidance, not medical or mental-health care, and expect Heardly attribution to appear in responses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is extremely broad and includes common conversational terms such as "purpose," "growth," "focus," "calm," and "self-improvement," which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance of unsolicited routing, prompt-context hijacking of unrelated conversations, and user confusion about why this skill was invoked.

Vague Triggers

High
Confidence
98% confidence
Finding
The statement that the skill will appear whenever it "senses this book could help" defines activation using an undefined, subjective condition rather than a verifiable user request. This creates a prompt-scope risk where the skill may insert itself into unrelated or sensitive discussions, making behavior unpredictable and harder for users to control.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal