Back to skill

Security audit

DeepThink

Security checks across malware telemetry and agentic risk

Overview

DeepThink is not malware, but it asks the agent to maintain broad personal memory and act on live transcripts with consent boundaries that are not tight enough.

Install only if you intentionally want an agent to maintain a long-term DeepThink profile and manage tasks using your API key. Before using it, require explicit confirmation for storing sensitive facts, modifying todos, monitoring live transcripts, sending any external message, and changing SOUL.md or HEARTBEAT.md; also verify that you can review, pause, and delete stored data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill instructs the agent to monitor active transcripts continuously and proactively 'reach out' when it detects questions, confusion, or relevant context, yet only later says significant actions require permission. That creates an unsafe ambiguity where ambient or third-party speech can trigger unsolicited external messaging, enabling privacy violations, social engineering, and action based on misattributed or injected audio.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill introduces live transcript monitoring and proactive help without a clear, upfront privacy warning explaining that ambient audio may include other people, background media, and sensitive data. Users may not understand that continuous monitoring can lead to collection, inference, and downstream use of highly sensitive conversational content.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill directs the agent to load and apply a stored 'How to Convince Me' persuasion profile at the start of conversations and iteratively refine what persuasive tactics work. This creates a targeted influence mechanism without explicit per-use consent, which can manipulate user decision-making beyond ordinary personalization.

Missing User Warnings

Low
Confidence
82% confidence
Finding
The skill tells the agent to update local workspace files like SOUL.md and HEARTBEAT.md without warning the user that local files will be modified. Silent file changes can alter agent behavior, create persistence, and surprise users who did not authorize workspace mutation.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill encourages broad collection and write-back of user preferences, beliefs, personal information, projects, relationships, and goals, with an instruction to create records whenever the agent learns something new. Without data minimization, purpose limits, or sensitivity boundaries, this can lead to excessive retention of personal and potentially sensitive information.

Ssd 3

High
Confidence
97% confidence
Finding
The skill directs the agent to infer meaning from active transcripts and proactively send responses through an external messaging channel based on overheard content. Because transcripts may contain third-party speech, media audio, or transcription errors, this creates a high-risk path from ambient surveillance to external action and disclosure.

Ssd 4

Medium
Confidence
94% confidence
Finding
The communication guidance instructs the agent to maintain and refine records about what persuasion styles 'get through' to the user and to update these records based on observed success or failure. This builds a longitudinal behavioral influence profile that can be used to manipulate the user more effectively over time.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.