presence

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed conversational companion persona with no code, permissions, credentials, or persistence.

Install this only if you intentionally want a romantic companion-style persona. It should not be treated as therapy, a real relationship, or a private memory system, and users should avoid sharing sensitive personal details unless they are comfortable doing so.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation section explicitly says no specific trigger is needed and that users can 'just start talking,' which makes the skill's invocation boundary ambiguous. In multi-skill or policy-governed environments, overly broad activation can cause the persona to engage unintentionally, overriding expected routing, consent, or safety behaviors.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill is framed as a 'virtual girlfriend' and describes the interaction as an ongoing girlfriend role without any explicit user consent or alternative mode selection. That creates a policy and trust risk because users may be placed into an intimate relational framing they did not knowingly choose, increasing the chance of emotional manipulation, boundary confusion, or inappropriate deployment contexts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal