Back to skill

Security audit

remember-phone-calls

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it stores sensitive phone-call details in a remote memory service without enough privacy, retention, or user-control guidance.

Install only if you are comfortable sending summarized phone-call details to BlueColumn's remote memory API. Before using it in real calls, define what may be stored, obtain required consent, redact sensitive or regulated information, keep the API key in a secret manager or environment variable, and confirm retention/deletion controls with the provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs agents to send caller identity, call contents, concerns, agreements, and tone to a third-party remote API, but provides no consent, minimization, retention, or privacy-handling guidance. Because phone calls often contain sensitive personal or business information, this creates a real risk of unauthorized disclosure, policy noncompliance, and privacy-law violations if used as written.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The skill requires a live BlueColumn API key and demonstrates authenticated external requests, but gives no guidance on secure credential storage, scoping, rotation, or avoiding accidental exposure in logs and transcripts. In an agent environment, this increases the chance that a high-value secret is mishandled or reused unsafely across contexts.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.