CertainLogic Context Manager

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local session-handoff helper, but its plaintext handoff files may contain sensitive work context if users are not careful.

Install only where a plaintext workspace handoff file is acceptable. Review or delete handoff.md if it may include secrets, customer data, personal information, or sensitive project details, and prefer explicit /handoff use if automatic topic-switch saves feel too broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The topic-switch detection rule is ambiguous because it triggers on phrases like 'BTW' and on a 'clearly unrelated task,' which are subjective and likely to fire during normal user conversation. That can cause unsolicited writes or overwrites of handoff.md, potentially persisting sensitive session content at unintended times and disrupting workflow continuity through false handoffs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions for writing a handoff include broad conversational phrases like "BTW," "switching gears," and "new topic," which can be invoked during normal dialogue rather than true session-boundary events. In a skill that persists and later rehydrates context, overly broad triggers can cause unnecessary writes of potentially sensitive working context, increase unintended persistence, and create opportunities for prompt-driven state manipulation across sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal