English-follower

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only English coaching skill with some overbroad activation risk but no code, data access, persistence, or hidden behavior.

Install this if you want short English rewrites and conversational practice; disable it or avoid broad auto-invocation if you find it taking over ordinary English-related conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough to activate on ordinary conversation about English, grammar, or expression, which can cause the skill to hijack interactions outside narrow user intent. Overbroad invocation increases the chance that the agent applies this skill in inappropriate contexts, leading to unintended behavior and policy conflicts.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hardcodes English-only behavior regardless of the user's language preference or explicit opt-in. This can override expected language handling and cause the agent to respond in an unwanted language, creating policy and usability failures when invoked implicitly through broad matching.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal