Action Items Tracker

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a meeting follow-up helper, with privacy caveats around broad activation and memory use but no evidence of malware, exfiltration, or destructive behavior.

Before installing, use this skill only on meeting notes you are comfortable having summarized and potentially remembered for follow-up. Avoid confidential, regulated, or highly sensitive meeting content unless the runtime gives you clear memory controls and a way to review or delete saved context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to activate on ordinary meeting- or task-related conversation, which can cause the skill to process content the user did not clearly intend to route through this workflow. In this skill, that matters because it can lead to unintended extraction of responsibilities and optional memory-backed follow-up behavior on potentially sensitive meeting notes.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs use of memory for follow-up and identity resolution ('eu' -> saved identity) but does not clearly warn users that meeting content and personal identity information may be stored for future sessions. This creates a privacy and consent problem, especially because meeting notes can contain sensitive internal plans, names, deadlines, and accountability information.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal