Back to skill

Security audit

Need A Hug

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed comfort-response skill with some routing and language-behavior caveats, but no evidence of hidden access, unsafe execution, exfiltration, or destructive behavior.

Install this only if you want the assistant to shift into a warmer comfort style when you sound distressed or ask for support. Review the implicit invocation behavior if you prefer comfort mode to require explicit commands, and use optional memory only for low-sensitivity preferences you intentionally choose to save.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest’s default prompt uses a broad emotional invocation phrase ('comfort me for a moment') and the policy allows implicit invocation, which can cause the skill to activate in many normal conversations involving stress, frustration, or sadness. Because this skill steers the agent into a counseling-like support mode, overbroad triggering increases the chance of unintended behavioral override, inappropriate emotional dependency cues, or suppression of the primary task when the user did not explicitly request this mode.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The protocol explicitly prescribes a Chinese-specific first-reply shape, which can override the user's actual language preference and lead the agent to switch languages without consent. In a sensitive emotional-support context, this can confuse users, reduce trust, and degrade safety by making crisis or comfort guidance less accessible if the user is not best served in Chinese.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.