Back to skill

Security audit

Sales Memory

Security checks across malware telemetry and agentic risk

Overview

This skill clearly provides sales-memory storage through BlueColumn, but users should treat it as sending customer and deal notes to an external persistent service.

Install only if you intend to use BlueColumn as an external persistent memory service for sales notes. Avoid sending regulated, confidential, or unnecessary personal/customer details unless you have approval and understand BlueColumn retention and access controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs agents to store and recall sales/customer context through an external persistent memory service, including example data containing a named prospect's objection and follow-up details, but it provides no user-facing warning or consent guidance about transmitting potentially sensitive business or personal data off-platform. In a sales context, this can lead to unauthorized disclosure of customer information, deal history, pricing discussions, and other confidential CRM-like data to a third party, especially if users assume the data remains local to the agent environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.