Back to skill

Security audit

humor-up

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only humor-writing skill with clear safety limits and no executable behavior or sensitive access.

Install this if you want an assistant to help write or improve humorous text. Be aware that broad prompts like photo captions or humor mode may add wit where you might prefer a plain response, so turn humor mode off or ask for a serious tone in sensitive contexts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The sample prompt section uses very broad natural-language triggers such as 'Tell me a joke about Mondays,' 'Caption this photo,' and especially 'Humor mode on,' which can match ordinary user requests and cause the skill to activate outside clearly scoped comedy tasks. Over-broad activation increases the chance the agent applies the skill in contexts where humor is inappropriate or where attached content and unrelated requests are pulled into the skill unnecessarily.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The top-level description says to use the skill when the user 'asks to make something funnier, wants a joke or witty take, needs a toast/greeting/icebreaker/caption, or enables humor mode,' which is broad enough to overlap with many routine conversations. This ambiguity can route ordinary drafting, image-captioning, or conversational requests into the skill, creating policy and quality risks if humor is injected where it is not desired.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.