Digaide Assistant

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill connects an agent to Digaide's memory service, and its requested API key and curl dependency match that purpose.

Install only if you trust Digaide with the memory and identity context your agent may send. Review Digaide's privacy and retention terms, avoid sending sensitive data unless necessary, use a scoped or dedicated API key if available, and be careful when setting DIGAIDE_API_BASE to a custom endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly promotes persistent identity, long-term memory, and use of external API endpoints, but it does not disclose that user data and conversation context may be transmitted to a third-party service or retained over time. In an agent ecosystem, this omission can lead operators to enable the skill without informed consent, increasing the risk of privacy violations, policy noncompliance, or unintended exposure of sensitive data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal