Back to skill

Security audit

PUA Breakthrough Mode

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only workflow skill that encourages a user’s agent to be more persistent, with no evidence of hidden code execution, data access, or destructive behavior.

Install this only if you intentionally want stronger task-persistence guidance. Treat it as a workflow aid, not permission to ignore safety policies, user confirmations, budgets, or caution on medical, legal, financial, account-changing, or other high-impact tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is very broad and uses generic trigger phrases such as coding, debugging, research, planning, and analysis, which overlap with a large portion of normal user requests. This can cause the skill to be invoked in many contexts where its 'push past shallow answers' and 'higher agency' behavior changes agent conduct more than the user explicitly intended, increasing the risk of overreach or unsafe persistence on sensitive tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation template uses broad, generic phrasing such as 'push this task past early stopping' and 'explore real alternatives,' which can plausibly match many normal user requests and cause the skill to activate outside clearly intended contexts. In this skill's context, that broad activation is more concerning because the behavior explicitly increases persistence and agency, which can amplify risky actions, reduce natural stopping points, and override safer default interaction boundaries.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.