Back to skill

Security audit

📡 Knowledge & Trends Engine

Security checks across malware telemetry and agentic risk

Overview

This skill matches its stated purpose, but it should be reviewed because it can persist and periodically reprocess user-derived memory and shared content without clear consent or deletion controls.

Install only if you want a persistent knowledge base built from prior conversations and shared content. Avoid using it with confidential, personal, legal, medical, financial, or proprietary information unless you have separate controls to review, delete, and keep stored notes private.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly persists summaries of user discussions and extracted content from shared articles, videos, and images into multiple memory tiers, but it does not clearly disclose retention behavior or obtain user consent before storing that data. This creates a privacy risk because users may share sensitive personal, professional, or proprietary information expecting transient processing, while the skill instead turns it into long-lived memory artifacts.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The scheduled self-review workflow states that the skill may autonomously review stored concepts, run external trend research, generate summaries, and log iterations without a fresh user request, yet this autonomous behavior is not clearly disclosed to the user. That increases privacy and governance risk because previously stored user-linked context can be reprocessed and combined with external data on a recurring basis, potentially broadening exposure beyond the user's original intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.