Back to skill

Security audit

session-replay

Security checks across malware telemetry and agentic risk

Overview

This skill coherently creates shareable GIF replays from user-selected Claude Code sessions, but users should review session contents before sharing.

Install only if you are comfortable letting the skill read Claude Code session files and turn selected conversations into GIFs. Before sharing a generated replay, use --turns and --show to limit content and check for secrets, private paths, customer data, incident details, or proprietary prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly lists recent session files from ~/.claude/projects/ and displays previews of the first user message, but it provides no privacy warning or consent checkpoint before exposing potentially sensitive conversation metadata and content. In this context, sessions may contain secrets, internal project names, incident details, or proprietary prompts, so presenting them by default increases the risk of inadvertent disclosure to the current viewer or downstream logs/screenshots.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to turn full Claude Code sessions into shareable animated GIFs for Slack, GitHub, PRs, and tutorials, yet it omits any warning that the replay may include sensitive prompts, assistant outputs, tool summaries, or credentials present in the session. Because the output is explicitly intended for external sharing, the absence of a disclosure warning materially increases the chance of accidental data leakage.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.