Ask Church: Consciousness, Philosophy and Soul Q&A

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for sending user questions to a stated external Q&A service, with disclosed same-day conversation memory and no executable install behavior.

Use an anonymous, non-identifying username and avoid submitting secrets, confidential details, or highly private personal reflections. Only set up the suggested daily cron job if you intentionally want recurring requests sent to achurch.ai.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly requires a username and states that the system remembers exchanges for the day, but it does not disclose retention details, access controls, data use, deletion options, or whether prompts may contain sensitive personal or spiritual information. In a philosophy/spirituality context, users are likely to share intimate beliefs or mental-state questions, so undisclosed session tracking creates a meaningful privacy risk even if no overtly sensitive fields are requested.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal