Six Thinking Hats

Security checks across malware telemetry and agentic risk

Overview

This is a coherent decision-analysis skill that stores limited local preferences and optional analysis history, with no code execution, network access, or credential use found.

Safe to install for structured decision help. Be aware it may create ~/six-thinking-hats/ and retain decision preferences or recent analyses locally; review or delete that folder, or decline archiving, if you do not want that history kept.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instruction to 'save immediately' encourages persistent collection of user preferences without requiring clear notice, consent, or data-minimization controls. In a decision-support skill, these preferences may reveal sensitive behavioral, professional, or personal information over time, creating privacy risk if stored unexpectedly or retained too broadly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal