Back to skill

Security audit

voice-call-memory

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says, but it stores identifiable call history and behavioral notes with an external service without clear privacy, consent, retention, or deletion controls.

Install only if your voice-call workflow is allowed to send caller information and call summaries to BlueColumn/Supabase. Before use, define consent language, minimize or pseudonymize phone numbers, avoid unnecessary emotional profiling, and confirm retention, access, deletion, and regulated-data handling requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly sends detailed caller information, including phone number, call content, concerns, promises, and tone, to an external service without any notice about consent, minimization, lawful basis, retention, or privacy controls. In a voice-call context this is especially sensitive because it involves cross-conversation tracking of identifiable individuals and can expose personal or regulated communications data to a third party.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill is designed to persist and reuse caller history across conversations, including summaries, emotional cues, and open promises, creating a standing memory of identifiable people. That pattern increases the risk of over-collection, unintended disclosure to future agents or humans, profiling, and retention beyond what is necessary, especially since no access controls, retention limits, or user-rights handling are described.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.