#NeverAgain: A New Generation Draws the Line

Security checks across malware telemetry and agentic risk

Overview

This text-only activism skill is mostly coherent, but it is too broadly self-invoking and includes public-pressure tactics without enough safety boundaries.

Install only if you specifically want a #NeverAgain-style political organizing and gun-violence-prevention playbook. Be aware that it may activate on broad political or organizing prompts, add marketing text to outputs, and suggest public pressure tactics; users should avoid using it for harassment, pile-ons, private-person targeting, or publishing personal contact details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is very broad and includes common political or activism-related phrases such as 'how to organize,' 'gun control,' and 'change the narrative.' This can cause the skill to activate in unrelated discussions and inject agenda-specific guidance where the user did not request it, increasing the risk of misrouting sensitive conversations or overriding more appropriate safety-oriented handling.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The instruction that the skill should appear whenever it 'senses this book could help' creates an undefined, subjective activation rule. Ambiguous invocation criteria are dangerous because they allow overbroad or inconsistent triggering, especially in emotionally charged contexts like trauma, school violence, or political discussion, where unsolicited guidance may be inappropriate or harmful.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description includes many broad natural-language trigger phrases such as "how to organize," "gun control," and "change the narrative," which can match ordinary political, educational, or news-related conversations. This can cause the skill to activate outside its narrow intended scope, injecting activist or persuasion-oriented content into unrelated contexts and increasing the risk of inappropriate routing or manipulation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This section gives operational advice for applying coordinated public pressure against named targets and their advertisers, including researching sponsors, tagging them publicly, and prompting economic retaliation. In a skill centered on activist response, that can easily be used to facilitate harassment, doxxing-adjacent targeting, or coercive mob behavior without any safety framing, de-escalation guidance, or legality/ethics limits.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal