Peace Love

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, instruction-only LLM self-review skill, with broad activation rules that may interrupt normal chats but no evidence of hidden code, persistence, or data exfiltration.

Install this if you want an LLM integrity-check workflow that can activate when you challenge the model's honesty. Avoid using it in highly sensitive conversations unless you are comfortable with the full chat being reviewed by a subagent and quoted in the resulting report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are intentionally expansive and include subjective cues like 'the LLM seems to be avoiding a clear answer' and 'any situation where the honesty or integrity ... is called into question.' That can cause the skill to activate during ordinary disagreement or uncertainty, interrupting normal task flow and encouraging unnecessary self-diagnosis loops, especially because the skill is user-invocable and says to ALWAYS trigger.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal