Back to skill

Security audit

digital-garden-cultivator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only digital garden skill with some broad activation terms and note-cleanup guidance users should review before acting on.

Before installing, treat this as a note-management aid: confirm any archive, move, or delete action before allowing the agent to change your garden files, and be aware that broad triggers may make the skill appear for general linking or documentation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The listed triggers include generic words and phrases such as "linking," "curation," and "documentation," plus a fragmentary phrase "or tracking content maturity." These are not narrowly scoped to this skill and could overlap with common requests unrelated to digital garden management.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The maintenance cadence states content may be "move[d] to archive or delete" after inactivity, which can affect user data. The markdown does not include a clear warning that this behavior may remove or relocate notes and should be reviewed or confirmed before use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.