Crimson DevLog

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent developer journaling helper, with ordinary risks from installing a Python CLI and saving local project notes.

Install this only if you are comfortable with setup.sh installing Python tooling and the current dev-log-cli package from PyPI. Avoid logging secrets, tokens, customer data, or confidential internal details unless you understand where the local SQLite database is stored and how to remove it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill explicitly states that it stores project milestones, statuses, and context in a structured SQLite database, but it does not clearly warn users that invoking the CLI persists potentially sensitive operational data to local storage. In an agent environment, silent persistence can expose internal project names, blockers, or workflow details to later users, other tools, or backup/sync processes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal