Back to skill

Security audit

Phy Lenny Mentor

Security checks across malware telemetry and agentic risk

Overview

This is a text-only product mentoring skill with disclosed proactive triggers and optional local transcript search, with no hidden code, persistence, credentials, or destructive behavior.

Install this if you want product advice surfaced during relevant conversations. For tighter control, invoke it explicitly with '/lenny-mentor' or 'ask lenny', and store any podcast transcripts or wisdom JSON in a dedicated folder without unrelated private company notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises automatic activation 'when relevant' and describes broad product-related triggers, which can cause the agent to invoke this skill in many ordinary conversations without explicit user intent. That increases the chance of unintended context capture, response hijacking, or the model prioritizing this persona over more appropriate tools, especially in mixed workflows.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger set includes common phrases and broad conversational patterns like product strategy, roadmap, prioritization, and 'teach me something,' making accidental activation likely. In practice, overlapping proactive and reactive triggers can cause unsolicited intervention, prompt-surface expansion, and increased risk that the agent follows this skill's instructions in contexts where the user did not request it.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.