Self Thinking Agent

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a prompt-only reasoning or self-reflection aid, with the main caveat that its activation wording may be broader than users expect.

Before installing, expect that the skill may activate on broad reasoning or self-reflection prompts. If you want predictable behavior, invoke it explicitly and consider narrowing its trigger wording, but the available evidence does not show malicious or unsafe capabilities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list is broad enough to match common phrases like 'reasoning' and 'self-reflection,' which can cause the skill to activate in ordinary conversations where the user did not intend to invoke it. Unintended activation can alter agent behavior, insert extra reasoning steps, or change response style in contexts where predictability and least-surprise matter.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal