Back to skill

Security audit

Learn English By Programmer Jokes

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed joke-appending skill that may be annoying in formal outputs but does not show hidden data access, exfiltration, or unsafe installation behavior.

Install this only where automatic bilingual programmer jokes at the end of responses are acceptable. Avoid loading it for JSON-only/API workflows, legal or medical tasks, crisis contexts, or formal professional answers where extra text could break parsing or look inappropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger condition is extremely broad: merely loading the skill and completing almost any user request causes it to modify the final response. This can create unintended behavior across unrelated conversations, reduce answer quality, and interfere with contexts where precision, professionalism, or policy compliance matter.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill mandates Chinese+English output regardless of the user's language, locale, or formatting expectations. Forcing an unsolicited language can violate product policy, degrade usability, and create trust issues in professional or sensitive interactions.

Natural-Language Policy Violations

High
Confidence
96% confidence
Finding
The output template hard-requires both English and Chinese joke fields in every triggered response, making the locale violation systematic rather than incidental. Because this is placed at the end of the final answer, it can also conflict with output-format constraints from other skills or user instructions.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The rule set instructs the agent to append a bilingual joke, including Chinese text in fallback options, regardless of the user's requested language or formatting constraints. This can cause unauthorized output modification, violate user expectations, and create prompt-level policy conflicts in contexts where exact output format, single-language responses, or strict schemas are required.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Required Behavior

- Append exactly one joke or quote when the trigger conditions are met.
- Do not ask the user whether to add a joke if this skill is already loaded.
- Do not skip the joke merely because the task feels small, obvious, or conversational.
- Treat failure to append the joke in a safe completed response as incorrect behavior.
Confidence
90% confidence
Finding
The instruction to append content autonomously and specifically not ask the user removes consent for a non-essential behavioral modification. While not a severe exploit by itself, it increases the chance of unrequested output and makes the skill more likely to override user expectations or product UX rules.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.