Daily Recommend

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed daily recommendation helper, with the main privacy consideration being its local preference history file.

Install this if you want proactive daily recommendations and are comfortable with a workspace file retaining likes, dislikes, ignored items, and preference weights. Review or delete that file if you do not want the history reused.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly records user reactions into a persistent preference file, but the skill text does not indicate any user notice, consent flow, retention limit, or access control for that behavioral data. Even though the stored data appears limited to recommendation preferences, it can still reveal tastes, moods, and inferred personal traits over time, making this a real privacy vulnerability in the context of repeated automated pushes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal