Handwriting Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill has no executable code, but it directs agents to make sensitive personality, mental-state, and criminal-risk judgments from handwriting in forensic and personnel contexts.

Install only if you understand this is speculative graphology guidance, not a reliable forensic, hiring, mental-health, or law-enforcement assessment tool. Do not use it to judge a person’s dangerousness, honesty, mental state, employability, or guilt, especially from third-party handwriting without informed consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes inferring personality, psychological state, and behavioral tendencies from handwriting, which is sensitive profiling based on biometric-style input. Although it includes a general limitations disclaimer, it does not warn about privacy risks, consent requirements, or the potential harm of making sensitive judgments about a person from their handwriting.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The skill is designed to generate personality, psychological, and behavioral judgments from handwriting by default, without requiring opt-in, narrowing scope, or preventing analysis of other people. In the stated criminal-investigation and personnel-evaluation contexts, this creates a heightened risk of unfair profiling, invasive inference, and misuse in high-stakes settings despite the methodology being subjective and unreliable.

Missing User Warnings

High
Confidence
97% confidence
Finding
This guidance explicitly maps handwriting traits to violent, fraudulent, and premeditated criminal tendencies, which can encourage users to infer dangerousness or guilt from pseudoscientific signals. In a forensic/investigative skill, that is especially risky because it may drive profiling, misclassification, and unjust suspicion despite the later disclaimer that the analysis is only auxiliary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal