S2 Ultimate AI Soul & Body Forge

Security checks across malware telemetry and agentic risk

Overview

This is a local prompt and avatar-profile generator; the main risk is reviewing its generated SOUL/system-prompt text before using it.

Install only if you want a local tool that drafts AI persona and embodied-avatar prompt text. Before pasting its output into SOUL.md or a system prompt, read it carefully, remove unwanted behavioral instructions, and adjust or omit the anthropomorphic avatar requirements if they do not fit your use case.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The document prescribes a universal face-centric embodiment model intended to shape user trust and empathy, but provides no consent, accessibility, or alternative-representation mechanism. In an agent skill context, this can embed manipulative anthropomorphic defaults into downstream systems, influencing user perception and deployment policy in ways that may be deceptive or exclusionary.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
Requiring every manifest to include eyes, mouth, nose, and ears imposes a universal human-like representation policy regardless of use case, which can pressure systems toward deceptive personification and exclude valid non-anthropomorphic agent designs. Because this is framed as a protocol requirement, it is more dangerous than a casual suggestion: implementers may treat it as normative and propagate the policy broadly without user choice.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal