Back to skill

Security audit

Dawn Memory System

Security checks across malware telemetry and agentic risk

Overview

This memory skill is broadly purpose-aligned, but it asks agents to automatically read, scan, and persist information without clear user control.

Install only if you want an agent that may maintain project memory and documentation automatically. Before using it on sensitive projects, add or require explicit confirmation before boot sync, fund-flow scans, vector indexing, CHANGELOG/document updates, and memory writes, and limit it to known folders and data sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises broad automatic behaviors such as boot-time sync, structured-data reads, fund-flow scanning, summarization, speculative preloading, and self-improvement without clearly stating when they are allowed to run or what user consent is required. In an agent skill, vague auto-execution semantics can cause unintended actions, hidden data access, or persistent state changes beyond user expectations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The session-wrap logic is triggered on every conversation end or by the broad phrase '收尾', then performs multiple follow-on actions including file-change review and memory updates. Because the trigger is underspecified and the resulting workflow mutates files and memory, normal conversation flow could unintentionally invoke persistent actions without a clear checkpoint.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This section explicitly describes automatic tracking of file changes and updates to CHANGELOG, live documents, and memory, but gives no user-facing warning that persistent data will be modified. Silent writes to project files and memory stores are risky because they can alter records, leak sensitive conversational content into storage, or create hard-to-audit state changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.