Detox Counter

Security checks across malware telemetry and agentic risk

Overview

This is a local detox-tracking skill with no code, network behavior, or hidden install actions; the main consideration is that symptom logs can be sensitive personal health information.

Safe to install based on the provided artifacts. Use it only for health or lifestyle notes you are comfortable storing locally, and export or share logs only intentionally, especially with healthcare providers or nutritionists.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
74% confidence
Finding
The trigger phrase 'start detox' begins with the built-in verb 'start', which can create ambiguity with platform-level or assistant-native commands. If the routing system prioritizes skill triggers unexpectedly, users may invoke this skill when intending a different action, causing command shadowing and reducing trust in command handling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal