Back to skill

Security audit

Sage Planning

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches a planning persona, but it includes an under-disclosed script that can send generated output to a hard-coded Feishu recipient.

Review before installing. The persona-planning behavior is straightforward, but do not run cron_trainer.sh or schedule it unless you intend generated output to be sent to the hard-coded Feishu target. Treat the local persona memory file as instructions that can influence the assistant, and review it if it already exists before adopting the persona.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation phrases are broad and overlap with common user requests such as 'make a plan' or 'analyze the architecture,' which can cause unintended triggering of the skill. In an agent environment, this can silently change behavior, load external persona instructions from memory, and alter how subsequent prompts are interpreted without clear user consent.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The skill instructs the agent to read a persona file and adopt that persona automatically, without indicating explicit user opt-in or safeguards. This can override normal assistant behavior and introduce prompt-injection risk from persona content, especially because the referenced memory file is external to this document and may contain adversarial or policy-conflicting instructions.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The script automatically sends generated output to an external Feishu recipient without any confirmation, classification, or guardrail on what the generated content may contain. In an agent/automation context, this increases the risk of unintended data exfiltration, especially if the topic or generated content can be influenced to include sensitive internal information.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal