Back to skill

Security audit

Conversa Analyzer

Security checks across malware telemetry and agentic risk

Overview

This is a simple transcript-analysis skill with no executable code or hidden behavior, though it requests broader file and memory-read permissions than its instructions clearly need.

Install only if you are comfortable giving the agent access to transcript files you point it at. For confidential chats or business records, avoid asking it to save outputs unless you explicitly want a written report, and be aware that memory_search/memory_get permissions may let the agent consult existing memory if enabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill is allowed to use write and memory tools, yet the description does not disclose that analyzed conversation content may be written or persisted. Because the skill processes potentially sensitive transcripts containing personal, business, or confidential information, users may unknowingly expose private data to files or memory stores.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.