Back to skill

Security audit

CertainLogic QM Timechain

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive, but it promotes broad company-wide access to real agent execution traces without documenting privacy, secret-redaction, or access-control safeguards.

Review before installing in a shared QM deployment. Use a least-privilege API key, restrict which workspaces or employees can query the data, and confirm with CertainLogic that traces are sanitized for secrets, PII, customer data, internal prompts, and tool outputs before exposing the corpus to agents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes organization-wide access to 75K+ real agent execution traces and 'every employee and project' access, but provides no guardrails around secrets, PII, customer data, internal prompts, tool outputs, or tenant scoping. In the context of QM, a company-wide multi-agent environment, this materially increases the risk of sensitive data exposure, overbroad retrieval, and accidental cross-project or cross-user leakage if traces contain production content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.