Back to skill

Security audit

MeritLoop Architect

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent product-design aid for Buddhist AI concepts and does not request code execution, credentials, or system access.

This appears safe to install as a concept and strategy skill. Users should treat its outputs as product brainstorming, not religious authority, and should separately review any real implementation that adds payments, temple integrations, personal practice logs, family sync, health-related guidance, or claims about merit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The line 'Use this file when the user wants naming help or a product gap review' is overly broad and lacks an explicit constraint tying activation to Buddhist/spiritual product work. In a larger agent system, this can cause the skill to be invoked for generic naming or product-review requests, exposing domain-specific content and steering outputs in unintended contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.