Back to skill

Security audit

learning-memory

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent, but it automatically sends interaction summaries to an external persistent memory service without clear opt-in, minimization, or deletion guidance.

Review this before installing if your learning conversations may contain private, regulated, or confidential details. Only use it with a BlueColumn key you control, and avoid storing secrets or sensitive personal information unless the platform provides clear deletion and retention controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs agents to send learning history and interaction-derived summaries to an external persistent memory service but does not clearly warn the user that their data will leave the local context and be retained remotely. This creates a privacy and consent risk, especially because learning history may contain sensitive personal, educational, or behavioral information that users may not expect to be stored externally.

Ssd 3

Medium
Confidence
98% confidence
Finding
The workflow explicitly instructs the agent to store a post-interaction summary via `/agent-remember`, which encourages automatic retention of user context in natural language. Because summaries can easily include sensitive details, preferences, credentials accidentally mentioned in chat, or other contextual data, this creates an ongoing data leakage and over-retention risk if stored without minimization or consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.