Personal Knowledge Base Lite

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local document knowledge base, but users should only point it at folders they are comfortable having indexed and summarized by the model.

Install only if you are comfortable with the selected folder's document contents being read for indexing and Q&A. Avoid broad locations such as your whole home directory, secrets folders, cloud-sync roots, or confidential work folders unless that is intentional; review or delete .kb-meta.json when you no longer want the generated summaries retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill indexes and answers questions by reading local files and sending extracted content, summaries, and possibly full document text to the LLM, but the description does not warn users about that data flow. This creates a privacy and consent problem: users may reasonably believe the tool is purely local when in fact sensitive document contents can be exposed to the model during indexing and Q&A.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal