Night Routine

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only night routine skill that fits its wellness purpose and shows no code execution, exfiltration, or hidden privileged behavior.

Safe to install based on the provided artifacts. Before using tracking features, consider that sleep habits, routine adherence, and next-day priorities can be personal; verify the host app's storage and deletion controls if that data is sensitive to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "wind down" is very generic and commonly used in everyday conversation, so the skill may activate unintentionally during unrelated chats about relaxing, ending the day, or reducing activity. In an assistant environment, overly broad triggers can cause misrouting, privacy surprises, or unwanted invocation of the skill when the user did not intend to use it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal