Back to skill

Security audit

Ontology KG

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local knowledge-graph memory skill, with the main risk being that it can persist information the user or agent chooses to store.

Install this only if you want a local long-term memory graph. Use explicit commands or confirmation before writes, avoid storing passwords, tokens, or confidential content directly, and inspect any external ontology.py script before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill defines trigger phrases such as "Remember that...", "What do I know about X?", and "Link X to Y" that closely match normal user conversation. In agent environments where skills are selected heuristically from natural-language prompts, this can cause unintended activation, leading the agent to read or write structured memory when the user did not explicitly request this skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.