Counterfactual Thinking

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only reasoning skill for counterfactual analysis, with broad activation wording but no code, data access, persistence, or hidden behavior.

Install this if you want the agent to use structured counterfactual reasoning for retrospective analysis. For medical, legal, security, mental health, financial, or other high-stakes topics, explicitly ask the agent to keep the analysis bounded and defer to appropriate domain safeguards.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is broad enough that an agent may invoke this skill for many loosely related conversations, causing scope drift and unintended application of the framework. While this is not directly code-execution or data-exfiltration risk, over-broad routing can lead to inappropriate handling of sensitive, regulated, or high-stakes topics without sufficient domain checks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Telling the agent to apply the framework to 'whatever the user is currently working on or asking about' is an open-ended instruction that bypasses meaningful scope limitation. In practice, this can cause the skill to be used on unsuitable topics, including sensitive personal, legal, medical, or security matters, where speculative counterfactual analysis may produce misleading or unsafe guidance.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal