Back to skill

Security audit

remember-birthdays

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it stores and recalls personal date reminders through a third-party BlueColumn/Supabase API, with privacy considerations users should understand.

Install only if you are comfortable sending names, special dates, relationship details, privacy preferences, and greeting-status notes to the BlueColumn/Supabase service. Use the minimum detail needed, avoid storing sensitive third-party information without permission, and check BlueColumn's privacy, deletion, and retention terms before relying on it for personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to transmit and persist sensitive personal data such as birthdays, anniversaries, memorial days, and named associations to a third-party endpoint without any privacy warning, consent guidance, retention notice, or data-handling constraints. This creates privacy and compliance risk because agents may collect and store personal data about identifiable individuals without informing users or limiting what should be sent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The workflow tells the agent to record that a greeting was sent, creating persistent interaction-history data tied to individuals, but does not warn that this user-related activity log will be stored. This is dangerous because it expands tracking beyond calendar facts into behavioral history, increasing privacy exposure and the chance of unauthorized profiling or over-retention.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.