Aquarium Assistant

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only aquarium care skill with some advisory safety caveats, but no hidden execution, data access, or abusive behavior was found.

Safe to install as a low-risk informational skill. Treat fish disease diagnosis, treatment suggestions, and sensor-based alerts as advisory; verify serious illness, medication use, or unusual water readings with trusted aquarium references, manual tests, or a qualified expert.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The metadata trigger list contains broad, everyday aquarium-related terms such as '养鱼', '鱼缸', '喂食', and '换水' without any scoping constraints. This can cause unintended invocation in normal conversation, increasing the chance the skill activates when the user did not explicitly request it and leading to inappropriate advice insertion or context hijacking.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The markdown trigger section repeats a long list of ambiguous activation phrases but does not define boundaries, exclusions, or examples of when the skill should not trigger. In practice, this broad matching can over-activate the skill during unrelated or only loosely related chats, creating reliability and safety issues through unsolicited recommendations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill offers AI photo-based fish disease recognition and treatment suggestions but does not warn users that image classification may be inaccurate or that wrong treatment can harm or kill animals. Because the feature presents a confidence score and treatment guidance, users may over-trust the output and delay proper expert diagnosis or apply unsafe interventions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes real-time water-quality monitoring and automatic alerts without cautioning that sensors can drift, fail, or be miscalibrated. Users may rely on incorrect readings for temperature or water chemistry decisions, potentially causing harmful husbandry actions or failure to detect dangerous conditions in time.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal