Back to skill

Security audit

Depression Support

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local depression-support skill with no evidence of hidden access, exfiltration, or unsafe automation.

Use this as self-help support, not medical care. Be aware it may activate on broad distress phrases, and if you are in crisis or outside the U.S., use local emergency services or a region-appropriate crisis line rather than relying only on the listed numbers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and directly overlap with common distress language, which can cause the skill to activate in sensitive conversations without clear user intent. In a mental-health context, unintended activation is more dangerous because it may interrupt other safety-critical handling, provide overly generic support where urgent triage is needed, or create false assurance for users in crisis.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The crisis section provides only U.S.-specific resources without clarifying geographic scope or offering alternatives, which can leave non-U.S. users without usable emergency guidance at the moment they most need help. In a depression-support skill, this context increases risk because users may reasonably rely on the provided crisis instructions and lose time if the numbers are not valid in their region.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.