Back to skill

Security audit

Algernon Feynman

Security checks across malware telemetry and agentic risk

Overview

This is a study helper that reads OpenAlgernon cards and can save session summaries, with no evidence of hidden or destructive behavior.

Install this only if you are comfortable with the skill reading your OpenAlgernon study database and saving study-session summaries. Configure the Notion option only with a trusted Notion CLI, account, and page ID, and avoid using it for sensitive study materials unless you are comfortable storing those summaries in Notion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a tutoring/study dialogue, but it also stores per-session results to external and local persistent destinations. That creates a data handling mismatch: users may disclose misunderstandings, study topics, or sensitive material during the session without realizing those details can be retained and exported.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Notion export introduces an external integration that is not necessary for the core Feynman tutoring function and expands the data exposure surface. If enabled, session summaries and weaknesses identified during study can be transmitted to a third-party service without a clear necessity or consent checkpoint.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill appends study-session metadata to a persistent memory file without any explicit warning, consent flow, or retention controls. Even if the log is summarized rather than full transcript, it still records learning history and weak points, which may reveal sensitive interests, educational status, or personal context over time.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Exporting session results to Notion without a clear privacy warning or affirmative consent can expose user study data to an external platform unexpectedly. Because the exported content includes weak points and review focus, it may contain sensitive personal performance information that users would not expect to leave the local environment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.