Test Curl 2

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed parenting and emotional-support skill with no packaged executable code or network behavior, though its activation language is broader than ideal for sensitive topics.

Install only if you want a Chinese-language parenting psychology support prompt. Treat it as educational support, not therapy or crisis care, and be aware that broad help-seeking phrases may activate the skill even when your request is only loosely related to parenting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes very broad distress phrases such as general help-seeking language, which can cause the skill to activate in contexts far outside parenting support. In a psychologically sensitive skill, accidental activation can misroute unrelated conversations into mental-health framing, creating inappropriate guidance, privacy overreach, or incorrect crisis handling.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Stating that 'any user input' can enter the analysis flow defines the scope too broadly and weakens topic isolation. This increases the risk that unrelated, sensitive, or adversarial input is processed as parenting or crisis content, leading to overcollection of context, false crisis escalation, or unsafe advice in the wrong domain.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal