Back to skill

Security audit

home-memory

Security checks across malware telemetry and agentic risk

Overview

The skill has a coherent home-memory purpose, but it would automatically send and retain household conversation summaries in an external memory service without clear user approval, limits, or deletion guidance.

Review before installing. Use it only if you are comfortable sending household context to BlueColumn, and avoid storing access codes, security details, identity data, financial information, or private contacts unless you have a clear retention and deletion plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly directs agents to send household context to an external persistent memory service but does not warn the user that potentially sensitive home-related data will leave the local agent context and be retained by a third party. Household notes can include addresses, landlord contacts, maintenance schedules, access details, and other private context, so lack of disclosure increases the risk of inadvertent exfiltration and privacy harm.

Ssd 3

Medium
Confidence
97% confidence
Finding
The workflow instructs the agent to automatically store a summary of each interaction to external memory after use, creating default retention of natural-language user data without any minimization or consent gate. In a home-management context, those summaries may accumulate sensitive operational and personal details over time, increasing exposure if the external service, credentials, or downstream retrieval are compromised.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.