Back to skill

Security audit

confucius-ai-conversation

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Confucius-style conversation skill with reference text only; its main risk is that broad triggers may make it activate for general life-advice questions.

Install this if you want general Confucius-style cultural dialogue and Analects-based advice. Be aware it may activate for broad life-advice prompts, so users who only want explicit roleplay activation may prefer narrower trigger wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is intentionally expansive, covering broad life-advice topics and many common terms. This can cause the persona skill to activate for general conversations outside the user’s clear intent, increasing the chance of inappropriate takeover of responses and bypassing more suitable domain-specific behaviors or safeguards.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation conditions include generic topics such as life, conduct, study methods, and wisdom-seeking, which are common across ordinary user conversations. In practice this may over-trigger the skill, causing response hijacking or misrouting and making the assistant answer in a roleplay style when the user did not specifically ask for that behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.