Back to skill

Security audit

remember-customer-names

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent as a customer-memory helper, but it sends and keeps customer personal details in a third-party service without clear limits or deletion controls.

Review this before installing in any customer-facing workflow. Use it only if your organization is comfortable sending customer profile notes to BlueColumn/Supabase, and configure agents to store only necessary, consented business context with a clear process for review, correction, and deletion. Avoid storing family, health, financial, or unrelated personal details unless there is a specific authorized business need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs agents to transmit rich personal data, including role, company, personal interests, and family details, to a remote third-party API without any privacy notice, consent requirement, retention limit, or data-handling warning. This creates a real risk of unauthorized disclosure of personal data, regulatory noncompliance, and overcollection of customer information beyond what is necessary for the stated purpose.

Ssd 3

Medium
Confidence
95% confidence
Finding
The workflow explicitly tells the agent to persist and reuse personal conversation details, including family, projects, and constraints, for future interactions. Persisting this type of personal context without guardrails encourages profiling and long-term storage of potentially sensitive information, increasing privacy harm if the store is misused, breached, or queried inappropriately.

Ssd 3

Medium
Confidence
96% confidence
Finding
The example payload normalizes building long-lived customer profiles containing personal preferences and family information ('son starts college in the fall'), which goes beyond ordinary contact management. Including such examples makes misuse more likely by encouraging agents to collect intimate details that are not necessary for customer service and may violate data-minimization principles.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.