Voku Language

Security checks across malware telemetry and agentic risk

Overview

This is a language-reference skill with no evidence of harmful data access or persistence, but it may activate broadly and references files/tools not included in the bundle.

Safe to install as an instruction-only Voku language reference. Be aware that some advertised references and the translator command are not included in this version, and do not run any separately obtained translator code unless you trust and review its source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and trigger terms are broad enough to activate on generic topics like conlangs, epistemic markers, or AI-to-AI communication, which may cause the agent to load this skill outside narrowly intended Voku tasks. Over-broad activation increases prompt-surface area and can lead to irrelevant instruction injection, context pollution, or accidental tool guidance being introduced into unrelated conversations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal