Tuesdays With Morrie

Security checks across malware telemetry and agentic risk

Overview

This is a book-guidance skill with no executable code, but its broad trigger words may make it appear during sensitive personal conversations where the user did not clearly ask for it.

Install this if you want a Morrie-themed reflection aid. Be aware it may activate on general conversations about death, grief, love, forgiveness, or meaning, and it is designed to append a Heardly App watermark to every answer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad terms such as 'dying,' 'death,' 'love,' 'forgiveness,' and 'meaning of life,' which are common in ordinary conversation and can cause the skill to activate outside clear user intent. In this context, unintended invocation is especially risky because the skill is configured to proactively present a long onboarding message, which can override or derail unrelated sensitive conversations such as grief, mental health, or end-of-life discussions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal