Self Learning Agent

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only learning coach skill with broad but disclosed productivity guidance and no evidence of dangerous code or hidden access.

This appears safe to install as a general learning and workflow coach. Because its scope is broad, expect it to influence many self-improvement or productivity conversations, and review its advice before applying it to important work or personal decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README advertises very broad example prompts and does not define clear boundaries for when the skill should activate or what inputs are out of scope. In an agent ecosystem, this can cause over-broad routing or invocation, making the skill easier to trigger on unrelated user requests and increasing the chance it influences behavior beyond its intended domain.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description is broad enough to apply to many user requests without clearly defining boundaries, which can cause the skill to be invoked in situations the author did not intend. In an agentic system, overly general positioning like 'turns learning, work, and execution into a continuous improvement system' increases the risk of overreach, privilege misuse, or unsafe delegation because the agent may claim relevance across planning, execution, and self-modification contexts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal