Ai Summary

Security checks across malware telemetry and agentic risk

Overview

This skill is a Zotero helper that saves paper metadata and optional AI summaries to the user's Zotero library, which matches its stated purpose.

Install only if you intend to let the agent add items to your Zotero library. Treat ZOTERO_CREDENTIALS as a private credential, and avoid saving confidential abstracts or AI summaries unless you are comfortable retaining them in Zotero.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly states that it saves AI knowledge summaries to a knowledge base, but it does not warn the user that invoking it causes persistent writes. This can lead to unintended storage of sensitive, proprietary, or personal information, especially in an agent context where users may not realize that content is being retained beyond the current session.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal