Back to skill

Security audit

customer-support-memory

Security checks across malware telemetry and agentic risk

Overview

This skill has a coherent support-memory purpose, but it directs agents to persist customer support history to a third-party memory service by default without clear privacy, consent, retention, or scoping controls.

Review before installing. This skill should only be used where your organization has approved BlueColumn for support data, has rules for what customer information may be stored, and has retention/deletion and access-control practices in place. Avoid storing billing, account, incident, or personal details unless explicitly authorized and minimized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly encourages storing customer support ticket content, including identifiable customer details and issue history, in persistent third-party memory without any consent, minimization, retention, or privacy guidance. In a support context this data often contains personal, account, billing, and incident information, so default persistence can create unnecessary long-term exposure and cross-session leakage risk.

Ssd 3

Medium
Confidence
95% confidence
Finding
The workflow directs the agent to recall prior support history and then store a summary after every interaction by default, which normalizes persistent retention of user interaction content without any conditional checks. That creates a practical risk of sensitive support details being accumulated over time and later surfaced to unrelated conversations, operators, or compromised integrations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.