Back to skill

Security audit

Problem-to-Action

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only planning skill with broad activation wording, but it has no executable code, hidden access, or persistence.

Install this if you want a structured 8-step problem-planning assistant. Be aware it may trigger on broad problem-related language, and do not rely on it for emergencies, self-harm, medical, legal, financial, abuse, or other high-stakes situations where qualified help is needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The call to 'Type your problem. Any problem.' uses unconstrained everyday language that can cause the skill to be invoked for sensitive, high-risk, or inappropriate domains without safety boundaries. In context, the skill claims it can turn any problem into an action plan in 10 minutes, which may lead users to rely on it for decisions requiring expert review or crisis handling.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list is very broad, including generic terms like '问题', '困难', and '不知道怎么办', which are common in ordinary conversation. This can cause the skill to activate unexpectedly and steer users into a rigid 8-step workflow even when they did not intend to use it, creating unsafe overreach and poor routing behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation rule says the workflow starts for 'any problem, dilemma, or contradiction' without scope limits or confirmation. In context, the skill is highly directive and requires mandatory step completion, so ambiguous auto-start increases the chance of hijacking unrelated conversations and pushing users into unnecessary data collection and process lock-in.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.