Waking The Tiger

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent trauma self-help guide, but it gives actionable trauma-processing exercises without enough safety limits or crisis/professional-care guidance.

Install only if you want a book-summary/self-help style trauma guide, not a clinical tool. Users should not rely on it for urgent distress, self-harm risk, severe panic, dissociation, psychosis, or unsafe situations; those cases need emergency support or a qualified trauma-informed clinician. VirusTotal and static scan were clean, and there is no evidence of malware-like behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This is a true safety vulnerability. The skill provides trauma-healing guidance and proactive instructions for users in a sensitive mental-health context, but it does not clearly state that it is not a substitute for licensed care or emergency support. In practice, a distressed user may rely on the skill instead of seeking urgent professional help, especially because the content is framed as authoritative, therapeutic, and immediately actionable.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file presents trauma-healing guidance in authoritative language, including claims that discussing trauma can retraumatize and that healing requires specific body-based methods, without any warning that this is not medical or mental-health advice. In a skill that may be consumed as actionable guidance, vulnerable users could delay seeking qualified trauma care, attempt self-treatment during dysregulation, or apply the advice to others unsafely.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file gives step-by-step trauma-processing exercises, including imaginal triggers, pendulation, titration, and defensive-response completion, without any warning that these practices can intensify distress, provoke dissociation, or be unsafe for some readers without clinical support. Because the skill is framed as practical techniques users can 'Listen and Execute,' readers may attempt self-guided trauma work beyond their window of tolerance, increasing the risk of psychological harm.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal