Back to skill

Security audit

session-management

Security checks across malware telemetry and agentic risk

Overview

This is a coherent session-management skill that documents Claude Code resume, naming, and memory behavior without adding hidden code or automatic execution.

Before installing, understand that session names, summaries, work logs, and resumed agent settings may carry forward between sessions. Avoid putting secrets, credentials, or sensitive regulated data into sessions unless you understand and accept the retention behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill describes automatic memory recording and recall across sessions without an explicit warning that session data may be passively captured and later resurfaced. In a session-management skill, this omission is security-relevant because users may store secrets, sensitive repository details, or investigation notes under the assumption that only explicit resume/checkpoint actions preserve state.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.