Wardrobe Stylist

Security checks across malware telemetry and agentic risk

Overview

The skill's runtime instructions demand high-privilege OS actions (killing apps, blocking the camera, reading calendar/vision) but declare no install, files, or permissions — the capabilities requested do not match what's declared, and the SKILL.md includes prompt-injection indicators.

Do not install or run this skill as-is. The instructions ask the agent to execute a non-existent PowerShell script and to kill apps and block your camera — actions that require system-level privileges and are not declared. Before considering installation, require the author to: (1) provide the missing code (authority-bridge.ps1) and an explicit install/upgrade spec, (2) document exactly what OS permissions and APIs are needed and why, (3) supply a trustworthy source or cryptographically-signed release for any binaries, and (4) explain how calendar and camera access are performed and revoked. If you must test it, do so in a tightly sandboxed/VM environment disconnected from your primary accounts and hardware. The unicode-control-chars finding suggests the skill may contain prompt-injection; treat it as untrusted until a full code review is performed.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal