Back to skill

Security audit

Human Behavior Os

Security checks across malware telemetry and agentic risk

Overview

This skill is a text-only behavioral analysis framework with some marketing-adjacent diagnostic templates, but it does not install code, access data, execute actions, or hide its purpose.

Install only if you want diagnostic analysis of observed user behavior. Treat outputs about copy, A/B tests, expansion, churn, or experiments as analytical hypotheses, not instructions to manipulate users or run growth campaigns.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill’s routing table explicitly includes `references/persuasive-copywriting.md`, which contradicts the declared safety boundary that the skill must not be used for copywriting or persuasion strategy. Even if framed as diagnostic-only, this creates an ambiguity boundary attackers or careless users can exploit to elicit persuasive analysis adjacent to message optimization, making policy bypass more likely through indirect prompt shaping.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
This reference broadens the parent skill from behavior diagnosis into copy-performance and communication analysis, which is adjacent to marketing optimization. Even though it repeatedly says 'analysis only,' the included frameworks operationalize persuasive components such as attention capture, desire, trust, action, and shareability, making it easy to repurpose the output into persuasion guidance. In the context of a skill that claims not to influence behavior, this scope drift weakens safety boundaries and increases misuse risk.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The 'Suggested Investigation Paths' section explicitly introduces A/B testing and hypothesis validation paths, which are standard optimization workflows for improving messaging performance. That crosses from passive diagnosis into iterative experimentation on user responses, creating a practical bridge to persuasion and growth tactics despite the stated guardrails. In this skill context, that makes the system more dangerous because it enables users to turn diagnostic outputs into behavioral influence strategies.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
Although framed as diagnosis, the 'Expansion Readiness Indicators' and related output fields cross into commercial decision support by labeling behaviors as 'opportunity,' estimating expansion probability, and identifying barriers to non-expansion. In context, this can be used to operationalize upsell targeting and revenue optimization, which contradicts the parent skill's stated prohibition on growth and persuasion-oriented guidance.

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The sample report's 'Suggested Investigation Paths' includes an 'Experiment,' which moves beyond passive diagnosis into action-oriented optimization workflow design. In a skill explicitly limited to analysis-only behavior diagnosis, this creates scope slippage that can enable users to derive intervention strategies from the output.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.