Back to skill

Security audit

family-memory

Security checks across malware telemetry and agentic risk

Overview

This skill openly provides family memory through an external service, but it stores sensitive family details persistently and automatically without clear consent, retention, or deletion controls.

Install only if you are comfortable sending family details to BlueColumn persistent memory. Avoid storing sensitive information about children, schedules, locations, health, finances, or private family matters unless everyone affected understands the risk and you know how to review and delete saved memories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description is broad enough to cause the skill to be invoked in loosely defined 'family coordination' scenarios, which increases the chance that highly sensitive family data is handled without clear necessity or user intent. In a memory skill tied to an external persistence service, over-broad triggering materially raises privacy and data-minimization risk.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly stores sensitive family details such as birthdays, school events, and other personal context in an external persistent memory service, yet provides no explicit privacy warning, consent flow, retention guidance, or data-sensitivity restrictions. Because the content concerns family members, including likely minors, the external persistence context makes unauthorized disclosure, overcollection, and long-term privacy harm more serious.

Ssd 3

Medium
Confidence
95% confidence
Finding
The workflow directs the agent to store a summary after each interaction, which encourages automatic persistence of conversation-derived family details regardless of whether the user asked for storage. This creates a systematic risk of collecting more personal data than necessary and silently exporting sensitive context to an external service.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.