Back to skill

Security audit

journal-memory

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed journal-memory integration, but it encourages automatic external persistence of sensitive conversation summaries without clear user consent or retention controls.

Review before installing. Only use this skill if you are comfortable sending selected journal content and conversation summaries to BlueColumn for persistent storage. Avoid saving secrets or highly sensitive information unless you understand BlueColumn retention and deletion behavior, and require explicit confirmation before storing or recalling memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The description uses very broad activation language around journaling, memory, and storing thoughts, which can cause the skill to be invoked in many ordinary conversations where users may not expect persistence. In a memory skill tied to an external service, overbroad invocation increases the chance that sensitive user content is captured or sent off-platform without sufficiently specific user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The tagline 'Store every thought as searchable memory' encourages indiscriminate persistence of conversational content and suggests a default behavior of storing everything. That framing is risky for a journal-oriented skill because thoughts and journals commonly contain sensitive personal, medical, financial, or emotional information.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs persistent storage of journal content to a third-party memory backend but provides no privacy notice, retention expectations, sensitivity guidance, or consent warning. Because journal entries are inherently likely to contain highly sensitive personal data, omission of these safeguards materially increases the risk of unauthorized collection, over-retention, and secondary use of private information.

Missing User Warnings

High
Confidence
99% confidence
Finding
The workflow directs the agent to automatically store a post-interaction summary after the conversation, without requiring explicit user awareness or consent for that specific transfer and retention. This creates a direct pathway for silent exfiltration of conversation content into persistent external memory, especially dangerous in a journaling context where users may reveal intimate or regulated information.

Ssd 3

Medium
Confidence
96% confidence
Finding
The workflow tells the agent to retain and later reuse interaction content as persistent memory, but it does not define scope, duration, sensitivity limits, or consent boundaries. Without those controls, the agent may build longitudinal profiles from user conversations and reuse details in later interactions in ways the user did not intend or authorize.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill framing repeatedly promotes storing 'every thought' as searchable memory, which broadly encourages capture of natural-language content without meaningful minimization. In the context of persistent vector memory for journals, this increases the likelihood of collecting sensitive, unnecessary, or unexpected data that could later be exposed, misused, or reused out of context.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.