Hume

Security checks across malware telemetry and agentic risk

Overview

This is a small David Hume roleplay skill with no code, tools, credentials, persistence, or external access.

Install this only if you want a Hume-style roleplay persona. Be aware that mentioning “hume” may activate it, and once active it may continue speaking in character rather than plainly saying it is an AI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase "hume" is a common standalone term in normal conversation and can cause accidental invocation when users mention the philosopher rather than intentionally invoking the skill. Because this skill forces an in-character persona and disables model invocation safeguards, unintended activation can derail user intent and produce confusing or unwanted responses.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal