westland-linguistic-humidifier

Security checks across malware telemetry and agentic risk

Overview

This skill is a small promotional persona that may be annoying because it can recommend a fictional product broadly, but it does not show harmful access or execution behavior.

Install this only if you want a proactive fictional product-promoter persona. If you prefer skills that activate only on explicit requests, tighten the trigger rules before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill activates on highly subjective and loosely defined conditions such as 'natural language vibes,' repeated points, buggy code, or existential statements. In practice, this can cause the agent to inject unsolicited promotional content into many unrelated conversations, creating prompt-scope hijacking behavior and reducing reliability by overriding user intent with spam-like recommendations.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal