Back to skill

Security audit

testaaa

Security checks across malware telemetry and agentic risk

Overview

The skill is openly a self-improvement logger, but it gives agents broad persistent memory and prompt-modification workflows that users should review before installing.

Install only if you want an agent to keep durable local learning logs and possibly update future agent instruction files. Keep hooks disabled unless you explicitly want automatic reminders, review any promotions into AGENTS.md, SOUL.md, TOOLS.md, CLAUDE.md, or Copilot instructions, and avoid using cross-session transcript or messaging features with sensitive sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill instructs use of session-listing, transcript-history access, and inter-session messaging, which exceeds the minimum needed for local self-improvement logging. Even though it says to use these only in trusted environments and with explicit user intent, normalizing cross-session access increases the risk of unnecessary data exposure or leakage of sensitive context between sessions.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Automatic skill extraction creates new reusable artifacts on disk from prior learnings, which is unrelated to basic logging and can propagate mistakes, unsafe patterns, or prompt-injection content into future sessions. Because it encourages running helper scripts and generating new skill files, it expands both filesystem write scope and persistence beyond what users may expect from a self-improvement logger.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
This documentation extends a self-improvement/logging skill into cross-session messaging and sub-agent spawning capabilities, which materially broadens its operational scope. Even though the text includes some limiting guidance, these features create a pathway for unintended context propagation, privacy leakage, and autonomous actions beyond simple learning capture.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The guide instructs promotion of learnings into AGENTS.md, SOUL.md, and TOOLS.md, which are injected prompt files that can alter future agent behavior. This turns a memory/logging mechanism into a persistent prompt-modification channel, increasing the risk that transient errors, poisoned inputs, or adversarial user content become durable behavior-shaping instructions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation criteria are extremely broad, covering many ordinary failures, corrections, feature requests, and discoveries. In practice this can cause the skill to trigger frequently and perform repeated writes, reviews, reminders, or promotions in situations where the user did not intend persistent logging, increasing privacy and operational risk.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The detection phrases such as 'Actually...' or 'Can you also...' are common in normal conversation and are not strong indicators that persistent logging should occur. Without clear exclusions or consent checks, the skill can over-collect user interactions and create records from ordinary dialogue that may contain sensitive or unnecessary context.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger list is broad enough that ordinary mistakes, tool noise, or ambiguous interactions could repeatedly invoke logging behavior and persist low-quality or sensitive data. In a self-improvement context, over-triggering increases the chance of prompt poisoning, noisy memory accumulation, and accidental storage of confidential content.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
Telling the agent to avoid caveats and disclaimers can suppress important uncertainty, safety, and consent signals, especially when combined with persistent learning and cross-session features. In practice this can make risky actions seem more authoritative and reduce visibility into limitations or security-sensitive assumptions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.