Back to skill

Security audit

道德经智慧

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable Daodejing philosophy guide with some broad activation wording but no evidence of unsafe system access or hidden behavior.

Install this as a general philosophical reflection aid, not as a substitute for technical, legal, medical, emergency, or mental-health support. If it activates when you wanted practical expert help, ask for the relevant specialist guidance instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes many broad, common emotional and workplace terms such as 焦虑, 内耗, 躺平, and 微观管理. This can cause the skill to activate in ordinary conversations where the user did not request philosophical guidance, potentially overriding a more appropriate skill or response path. In this context, the content is non-executable and not directly harmful, but unintended invocation can still degrade safety by misrouting users away from domain-specific help.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage section says the system will automatically determine whether the skill is suitable, but it does not define clear gating criteria or require user consent before applying this philosophical framework. Ambiguous auto-invocation increases the chance of the skill engaging in situations where technical, legal, medical, or crisis-specific guidance would be more appropriate. Although the skill does contain some refusal guidance, the activation ambiguity still makes accidental misapplication plausible.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.