Life Alignment Agent

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed personal planning skill that stores sensitive self-reflection notes, but the behavior fits its stated purpose and shows no hidden code or exfiltration.

Install this only if you want a dedicated planning agent that remembers personal goals, values, decisions, patterns, and follow-up commitments. Review and prune the generated workspace files, avoid storing highly sensitive journals or test results unless needed, set clear heartbeat cadence and stop conditions, and do not treat the agent as professional medical, legal, financial, or mental-health advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill instructs automatic invocation whenever a conversation is 'clearly about life planning, real-world tradeoffs, action alignment, or proactive follow-up,' which is a broad set of common topics. In a dedicated agent, this can cause the skill to activate without explicit user intent, increasing the chance of context hijacking, misrouting benign conversations into durable-memory workflows, or applying strong recommendations where a narrower skill or neutral assistant behavior would be safer.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Several example triggers are generic everyday phrases like 'What should I do now?' or 'Should I do it?', which can appear in many contexts unrelated to this skill's intended scope. This broad overlap makes accidental activation more likely, which is risky because the skill is designed to learn persistent user values, patterns, and commitments over time.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is very broad and authorizes a persistent, strongly opinionated planning and decision agent without defining scope boundaries, allowed domains, or trigger constraints. In practice this can cause over-delegation into sensitive areas such as health, legal, financial, or high-stakes life decisions, increasing the chance of unsafe recommendations or inappropriate autonomous guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal