Back to skill

Security audit

Aioom

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a memory tool, but it needs review because it can run a background process that kills processes and it adds disk cleanup outside the advertised memory purpose.

Install only if you intentionally want a Windows memory guardian that may terminate processes. Use dry-run first, review targets before cleanup, and be cautious enabling background mode. Also review or remove the storage-clean integration unless you explicitly want this memory skill to trigger disk scanning and cleanup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a memory-management tool, but it also introduces storage scanning and disk cleanup capabilities that materially expand its authority and destructive potential. This scope creep is dangerous because users or orchestrators may grant trust based on the advertised memory purpose while the skill can also invoke separate cleanup logic on arbitrary paths.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The documentation directs the skill to execute an external disk-cleaning tool and open file-based reports even though these actions are unrelated to memory guarding. That hidden capability increases attack surface and trust confusion: a user asking about memory could be routed into file-system inspection or deletion workflows they did not anticipate.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger examples for storage actions use broad everyday phrases such as asking to 'look at storage' or 'clean disk junk,' which can cause accidental invocation of destructive cleanup behavior. In a skill that can call external cleaners, ambiguous language materially raises the chance of unintended execution.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill describes identifying and killing 'high-risk' processes but does not prominently warn that terminating processes can disrupt applications and cause data loss. Because the core feature is destructive process termination, lack of clear warning can lead users to authorize risky actions without understanding consequences.

Missing User Warnings

High
Confidence
94% confidence
Finding
The background monitoring instructions show how to launch a persistent daemon that can automatically clean memory, yet they do not clearly state that the daemon may autonomously terminate processes while running. A persistent unattended process-killer is more dangerous than one-shot commands because it can repeatedly affect user workloads without fresh consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.