Legal Essentials

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only legal education skill with a broad trigger, but it has no code, installs, credentials, persistence, or data-sending behavior.

Install only as a general starting-point guide. Do not treat it as attorney advice, verify jurisdiction-specific requirements, and avoid sharing sensitive legal, financial, or personal details unless necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase "legal" is overly broad and can cause this skill to activate in many unrelated conversations that merely mention legal topics. Because the skill provides generalized legal guidance, over-triggering increases the chance the agent injects jurisdiction-specific or incomplete legal information into contexts where it is not appropriate, potentially leading users to rely on advice outside the skill’s intended scope.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal