Back to skill

Security audit

voice-memory

Security checks across malware telemetry and agentic risk

Overview

This skill is not visibly malicious, but it asks agents to store and recall caller conversations indefinitely through a third-party service without enough privacy or retention controls.

Review this before installing for any real caller, customer, meeting, coaching, sales, or journal data. Only use it where callers have appropriate notice or consent, where BlueColumn retention and deletion policies are acceptable, and where you can minimize or redact sensitive transcript content and separate memories by caller or account.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly demonstrates sending phone numbers and call transcript content to a third-party service, but provides no privacy notice, consent guidance, data minimization advice, or handling restrictions. In a voice-agent context, this is dangerous because callers may disclose sensitive personal, financial, health, or business information during calls, and the example encourages transmitting and storing that data externally by default.

Ssd 3

Medium
Confidence
96% confidence
Finding
The repeated claims that the agent "remembers forever" and the recall example encourage indefinite retention and broad retrieval of past caller conversations. That creates a natural-language data leakage risk because highly sensitive historical conversations can later be surfaced to the model or operator in unrelated contexts, increasing exposure, overcollection, and the chance of unauthorized disclosure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.