Back to skill

Security audit

Daily Log

Security checks across malware telemetry and agentic risk

Overview

This skill is a local daily work journal for agents, with disclosed file persistence but no evidence of hidden, destructive, or external data-sharing behavior.

Install this only if you want agents to keep local daily work logs. Review the generated memory/daily files periodically, because they can preserve command output, file paths, errors, and other project details that may be sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The spec explicitly instructs the agent to read an existing diary file and write back merged content, while also saying not to delete old content and to perform incremental optimization. That is a real user-data modification capability without any requirement for user confirmation, preview, or rollback, which can lead to unintended overwrites, corruption, or persistent disclosure of sensitive session details in memory files.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.