Back to skill

Security audit

remember-preferences

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it sends named personal preferences to a remote service and tells agents to store them immediately without clear consent, deletion, or data-minimization guidance.

Review this before installing if you handle personal, workplace, or sensitive preferences. Use it only where users understand that their preferences may be sent to BlueColumn/Supabase-hosted endpoints, and avoid storing sensitive details unless the user explicitly agrees.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs agents to send named user preferences, communication habits, scheduling constraints, and feedback style to a third-party remote API, but it provides no explicit warning, consent requirement, retention guidance, or data-minimization constraints. Because preference records can contain personal or sensitive behavioral data tied to identifiable users, this creates a real privacy and data-governance risk if agents store such data automatically.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.