Back to skill

Security audit

Philosophy Dialogue Publish

Security checks across malware telemetry and agentic risk

Overview

This is a text-only philosopher-perspective skill whose main issue is broad activation wording, not security-sensitive behavior.

Install this only if you want the assistant to adopt philosopher or thinker viewpoints in relevant chats. Use explicit prompts when possible, because the broad triggers may activate when you merely discuss names or multiple perspectives; also note that the referenced full perspective library is not included in the submitted artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description explicitly says that entering any person's name can activate a perspective, which is far broader than a narrowly scoped invocation rule. In normal conversation, users frequently mention names, so this can cause accidental skill activation, unintended persona switching, and prompt-context hijacking that changes how the assistant responds without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase '多视角讨论' is generic and commonly used in ordinary discussion, making unintentional activation plausible. While this is not directly code-execution or data-exfiltration risk, it can cause the assistant to enter the skill unexpectedly and alter behavior, which is a prompt-safety and reliability issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.