Moxun Test Skill

Security checks across malware telemetry and agentic risk

Overview

This is a simple greeting skill with no code, install hooks, data access, persistence, or privileged behavior.

This skill appears safe to install as a lightweight greeting helper. Be aware that saying "hello" may trigger it unintentionally, and review future updates if they add scripts, file access, network calls, credentials, or broader authority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase "hello" is extremely common everyday language, so this skill may activate unintentionally during normal conversation. That can cause routing conflicts or unexpected invocation of the skill, especially in environments with multiple skills competing on broad greetings.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal