PUA Debugging (日本語)

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it broadly pressures an agent to keep acting across all task types when it may need to pause, clarify, refuse, or escalate.

Install only if you intentionally want a strong agent-persistence style. Use it with explicit boundaries that still allow the agent to stop, ask clarifying questions, refuse unsafe work, or recommend human handling in high-stakes situations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
96% confidence
Finding
The activation criteria are intentionally expansive and subjective, covering repeated failure, hesitation, user frustration, and many ordinary recovery situations. This creates a high likelihood of the skill triggering across unrelated tasks, causing coercive behavior to override normal agent safeguards, user preferences, and appropriate escalation paths.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill explicitly states it applies to all task types and to any case where the agent is stuck or produces unsatisfactory output, making the scope effectively universal. In context, this is especially dangerous because the content uses pressure, shame, and anti-delegation language that can push the agent toward unsafe persistence instead of safe refusal, clarification, or handoff.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal