Basketball

Security checks across malware telemetry and agentic risk

Overview

This is a basketball coaching and analysis skill with disclosed, optional local notes and no executable code or credential use.

Install this if you want structured basketball analysis. Before enabling memory, decide whether roster, player, opponent, or practice details should be saved in ~/basketball/, and choose explicit-only activation if you do not want the skill to engage during casual basketball discussion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The setup instructs the agent to activate basketball help whenever the user mentions broad basketball-related topics, including proactively in common discussion areas. This can cause over-triggering, where the skill engages without clear user intent, increasing the chance of collecting unnecessary context or steering conversations into persistent memory flows the user did not explicitly request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal