Back to skill

Security audit

remember-legal-research

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent legal-research memory tool, but it sends and recalls potentially confidential legal work through an external service without enough user control or matter-level scoping.

Review before installing for any privileged or client-confidential legal work. Use only if you are comfortable sending research notes to BlueColumn's external service, and avoid storing client names, strategy, privileged analysis, or matter-specific facts unless you have confirmed authorization, retention, deletion, and access controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs agents to POST detailed legal research content, including questions, sources, holdings, citations, and reasoning, to an external Supabase-hosted endpoint using a live API key, but provides no warning about confidentiality, privilege, or work-product exposure. In a legal-research context, these payloads can contain highly sensitive client strategy and privileged analysis, so silent transmission to a third-party service creates a meaningful data-leak and compliance risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The recall flow instructs the agent to retrieve prior legal research threads from an external service at the start of a session without warning that prior-session data has been remotely stored and may be reintroduced into the current context. For legal work, this can surface privileged matter history, client-specific strategy, or cross-matter data unexpectedly, increasing the risk of confidentiality breaches and improper data mixing.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.