Tell Jokes

Security checks across malware telemetry and agentic risk

Overview

This is a simple joke-telling skill with no code, installs, credentials, file access, or hidden privileges.

Install this if you want the agent to tell jokes on request. Be aware it may treat vague comments about boredom or wanting cheering up as an invitation to joke, and it supports dark humor when asked, but it does not add system access or handle sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description uses broad activation phrases such as 'wants to be cheered up,' 'says they're bored,' and 'requests something funny,' which can overlap with ordinary conversation and cause the skill to trigger when the user did not explicitly ask for a joke. Over-broad routing can lead to incorrect skill selection, reduced reliability, and unintended responses, especially in mixed-context chats where humor is mentioned incidentally.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal