Back to skill

Security audit

documentation-memory

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides documentation memory through an external BlueColumn service, but users should avoid storing sensitive or confidential material unless they explicitly intend that.

Install only if you want documentation context stored in BlueColumn. Do not store secrets, credentials, personal data, customer data, or confidential internal documents unless your organization has approved that use and you understand BlueColumn retention and access controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs agents to store and recall documentation in an external persistent memory service, but it provides no guidance on screening sensitive content, obtaining user consent, setting retention limits, or handling confidential/internal documents. In agent workflows, documentation often contains internal URLs, credentials-adjacent setup details, customer data, or proprietary operational context, so silent persistence to a third-party service creates a real data-leakage and privacy risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.