Nm Memory Palace Digital Garden Cultivator

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a documentation/digital-garden helper with only a minor routing concern and no evidence of hidden or harmful behavior.

Installers should be aware that the skill may activate for generic linking, curation, or documentation requests. Review whether those triggers fit your workflow, but the supplied evidence does not show behavior that requires Review or blocking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad generic terms like "linking," "curation," and "documentation," which can cause the skill to activate in many contexts unrelated to digital garden management. Over-broad activation increases the chance of unintended invocation, which can confuse agent routing, override more appropriate skills, or expose users to actions and guidance outside the intended scope.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal