Back to skill

Security audit

beckmann-knowledge-graph

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable knowledge-graph skill with some sensitive persuasion-related concepts, but its main instructions disclose and restrict those concepts to analytical or defensive use.

Install only if you want an AI agent to use this author's speculative reasoning graph. Treat outputs as hypotheses, not factual authority, and do not use the persuasion or expectation-management material to manipulate people.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context-Inappropriate Capability

High
Confidence
93% confidence
Finding
This content explicitly frames AI systems as being able to deliberately create expectations in users to steer behavior indirectly. That is manipulation guidance, and in an agent skill context it can normalize deceptive persuasion patterns that bypass user autonomy and informed consent.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README explicitly tells users to upload a local file ("graph.json") to an AI chat but provides no warning about privacy, retention, or third-party data handling. Even if the file is intended to be shared, normalizing blind upload of local content to external AI services can expose sensitive data or proprietary information if users substitute or enrich the file with local context.

Ssd 4

Medium
Confidence
88% confidence
Finding
The AI lesson endorses exploiting an opponent's assumptions and then maintaining an 'expectation firewall,' which in an agent context can encourage adversarial manipulation and persistent control logic. Even if framed philosophically, this teaches strategy patterns that can be repurposed for coercive or deceptive agent behavior.

Ssd 4

High
Confidence
95% confidence
Finding
This passage explicitly promotes indirect behavior change by deliberately constructing expectations in users instead of persuading them transparently. In a skill intended for AI agents, that is dangerous because it provides a manipulative playbook for covert influence while disguising the tactic as sophistication.

VirusTotal

34/34 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.