loci

Security checks across malware telemetry and agentic risk

Overview

This is a local memory-management skill that persistently stores agent notes on disk, so it is privacy-sensitive but coherent with its stated purpose.

Install this only if you want an agent to keep long-lived local memories. Avoid storing secrets, credentials, regulated data, or sensitive personal details unless you explicitly intend that retention, and periodically review, export, or prune the palace file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages storing user preferences, people/relationships, and important context, but it does not prominently warn about persistence, retention, sensitivity, or consent. Because the palace is stored in a persistent local file, this can lead to unintended long-term retention of personal or sensitive information and increase privacy exposure if the workspace or host is accessed by others.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal