Back to skill

Security audit

Voice Memory Features

Security checks across malware telemetry and agentic risk

Overview

The skill is transparent about providing voice-agent memory, but it encourages broad external storage and recall of calls, journals, meetings, and caller history without clear consent, scoping, retention, or access controls.

Install only if you are comfortable sending voice transcripts, caller/customer details, journal entries, meetings, coaching notes, and sales history to BlueColumn for searchable recall. Before production use, add explicit participant consent, redact sensitive content, avoid raw phone numbers as memory identifiers, define retention/deletion rules, and gate recall by verified user or caller identity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill explicitly promotes automatic memory of every conversation and continuity across calls, which encourages blanket retention and reuse of voice content without any mention of consent, minimization, or access controls. In a voice-agent context, this can capture highly sensitive personal, financial, health, or business information and later surface it to the wrong interaction or user.

Ssd 3

High
Confidence
97% confidence
Finding
Instructing the system to store every spoken thought as searchable memory directs indiscriminate collection of potentially sensitive content, including secrets, credentials, health details, legal matters, or private reflections. Making this content searchable further increases the chance of later disclosure through prompt injection, overbroad retrieval, or mistaken identity matching.

Ssd 3

Medium
Confidence
90% confidence
Finding
The meeting-memory feature directs recording, transcription, summarization, and storage of meeting content, which often contains confidential business information, HR issues, customer data, or regulated material. Without clear controls for consent, participant notice, retention, and authorization, this creates substantial risk of privacy violations and internal data leakage.

Ssd 3

Medium
Confidence
94% confidence
Finding
The example stores conversation details tied directly to a phone number, which links behavioral data to a personal identifier and increases re-identification and unauthorized profiling risk. If recalled in later sessions or exposed through logs, prompts, or retrieval, the agent could disclose one caller's preferences or history inappropriately.

Ssd 3

High
Confidence
98% confidence
Finding
The workflow instruction to store the full transcript after each call encourages broad, automatic retention of user communications regardless of sensitivity or necessity. In a voice-agent environment, full transcripts can include authentication details, payment data, health information, or confidential discussions, making blanket storage especially dangerous.

Ssd 3

High
Confidence
95% confidence
Finding
The function explicitly recalls 'everything' known about a caller, including preferences, history, and open items, and returns it for use before answering. In a voice context, this creates a significant privacy risk because sensitive personal data can be surfaced or injected into responses without verifying caller identity, minimizing scope, or enforcing purpose limitation.

Ssd 3

Medium
Confidence
91% confidence
Finding
The module-level design instructs the system to recall relevant memories before answering and inject context into any voice response, which broadens the chance of unintended disclosure. Because this behavior is generic and automatic, it can leak stored personal or sensitive information into responses even when that context is unnecessary or should remain hidden.

Ssd 3

Medium
Confidence
72% confidence
Finding
The phrase 'automatically remember every conversation' signals a privacy-invasive design intent for pervasive collection of user communications. In a voice-memory skill context, this is more dangerous because it encourages blanket retention of potentially sensitive audio-derived text without any visible consent, minimization, or policy checks in this module.

Unpinned Dependencies

Low
Category
Supply Chain
Content
httpx
Confidence
98% confidence
Finding
httpx

Known Vulnerable Dependency: httpx — 2 advisory(ies): CVE-2021-41945 (Improper Input Validation in httpx); CVE-2021-41945 (Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `http)

Critical
Category
Supply Chain
Confidence
89% confidence
Finding
httpx

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.