Back to skill

Security audit

conjecture-prover

Security checks across malware telemetry and agentic risk

Overview

This skill does not show malware-like behavior, but it is risky because it presents an unaccepted proof of the Riemann Hypothesis as completed fact.

Review carefully before installing. The main risk is not system compromise; it is authoritative mathematical misinformation. Treat the bundled RH proof and any generated proofs as speculative drafts unless independently verified by qualified mathematical review, and avoid using this skill as a source of established results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The requirements file asserts that the Riemann Hypothesis is solved and that the skill contains a complete proof/case, which is factually false and can cause the agent to present fabricated mathematics as established truth. In a skill designed to 'prove conjectures,' this materially increases the risk of authoritative misinformation, invalid outputs, and user deception, especially because the false claim is embedded as normative task guidance rather than clearly labeled fiction or a hypothetical example.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad English activation terms such as 'prove conjecture' and the generic umbrella term 'meta-skill-system', which can cause the skill to activate in contexts far beyond the author's intended scope. Overbroad triggers increase the chance of accidental invocation, prompt-routing collisions, and inappropriate application of the skill's instructions or embedded reference workflow to unrelated user requests.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.