Truth first

Security checks across malware telemetry and agentic risk

Overview

Truth First is a verification workflow skill that asks the agent to check evidence before answering, with no hidden persistence, destructive behavior, or data exfiltration found.

Install this if you want stricter evidence checks before the agent answers. On sensitive systems, use command approval and ask the agent to redact secrets or avoid printing full config, log, or .env lines unless necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The README says the skill is "automatically triggered for verification tasks" with no clear boundary for what counts as a verification task and no exclusion examples. This broad activation description could overlap with many ordinary requests to check, confirm, or inspect something, increasing the risk of unintended invocation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal