Dream Maker

Security checks across malware telemetry and agentic risk

Overview

This is a coherent dream-writing skill that saves generated dream text locally, with no evidence of hidden or harmful behavior.

Install this if you want generated dreams saved as local markdown files. Be aware that it keeps a persistent dream archive and tracking log under `memory/dreams/`, so avoid including sensitive personal details unless you are comfortable retaining them there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to write files under `memory/dreams/` and update a tracking log, but it provides no requirement to obtain user confirmation or clearly disclose that persistent storage will be modified. In an agent environment, silent writes can create unexpected state, privacy issues, or auditability problems even if the content being written is non-executable dream text.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal