Back to skill

Security audit

metacognitive-self-mod

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent and not destructive, but it persistently records broad execution traces without clear privacy or redaction controls.

Review before installing if you work in sensitive repositories or regulated environments. The skill appears local and purpose-aligned, but it may save file paths, tool targets, decision rationales, and workflow metadata from skill runs; use it only where that local trace history is acceptable and periodically clear ~/.claude/skills/traces if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly records execution traces including tool targets, rationales, decision points, and stores raw JSON trace files under a persistent local path, but it provides no safeguards, redaction rules, or warning that file paths, code locations, prompts, and other sensitive project metadata may be captured. In a self-improvement skill that observes arbitrary skill executions, this broad capture scope increases the chance of unintentionally collecting secrets, proprietary code references, or system information and then retaining them for later analysis.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.