Back to skill

Security audit

Skill Sedimentation

Security checks across malware telemetry and agentic risk

Overview

The skill openly implements persistent self-learning, but it can automatically record task experience and modify memory or skill files without a fresh user request each time.

Install only if you want the agent to maintain an ongoing local experience bank and potentially adjust future behavior from prior tasks. Review or constrain what may be recorded, especially for tasks involving secrets, credentials, regulated data, private client information, or changes to existing skills/rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The skill is designed to auto-trigger after many routine task completions and then perform persistent memory writes and possible rule promotion without requiring explicit user initiation. In an agent setting, broad autonomous activation increases the chance of over-collection, unwanted persistence of sensitive task content, and self-modification behavior being exercised in contexts where it is unnecessary or unsafe.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.