Mystical Divination Toolkit

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide user-requested divination or numerology guidance, with no evidence of hidden execution, persistence, credential use, or data exfiltration.

Install only if you want entertainment-style divination or numerology responses. Avoid using it for medical, legal, financial, or other high-stakes decisions, and provide birth-date information only when you clearly intend to run a life-path calculation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
Advertising 'natural language triggers' without explicit activation boundaries can cause the skill to activate on ordinary user phrasing and steer responses into divination behavior unexpectedly. In an agent setting, broad trigger surfaces increase the chance of prompt-routing mistakes, unintended invocation, and misleading advice being produced in contexts where the user did not clearly request this skill.

Vague Triggers

Low
Confidence
79% confidence
Finding
The starter phrase 'calculate my life path' is generic enough to overlap with normal conversation, especially in systems that auto-select skills from user utterances. This can lead to accidental collection of birth-date information or initiation of pseudoscientific guidance when the user may not have intended to invoke the skill explicitly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal