Taiwan

Security checks across malware telemetry and agentic risk

Overview

This is a Taiwan travel-planning skill with local trip memory and no evidence of hidden code, network activity, credential access, or unrelated system control.

Install only if you are comfortable with Taiwan trip details and preferences being saved locally in ~/taiwan/ and possibly reused in future planning. Avoid storing highly sensitive information such as passport numbers, payment details, passwords, or full identity documents; review or delete the saved memory if you no longer want it retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation condition 'Read this when `~/taiwan/` doesn't exist or is empty. Start naturally.' is vague enough that an agent may trigger the setup in unintended situations, causing hidden instruction loading outside the user's clear request. While not directly data-exfiltrating or overtly malicious, ambiguous startup cues can expand the skill's influence and make behavior less predictable or auditable.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to ask to keep preferences handy and then 'Save their answer to main memory,' but it does not warn the user what data will be stored, how long it may persist, or how it could affect future interactions. This creates a privacy and consent problem because travel preferences can become retained personal profile data without meaningful transparency.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal