Ai Evolution Engine V2

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious, but it asks agents to change persistent memory/instruction files and install more skills without concrete limits or enforced approval.

Install only if you want an agent self-improvement helper and are prepared to supervise it closely. Do not allow it to edit MEMORY.md, AGENTS.md, SOUL.md, knowledge files, or install additional skills unless you first review an exact diff/source and explicitly approve the change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly advertises self-modifying behavior such as updating MEMORY.md/knowledge, optimizing AGENTS.md/SOUL.md, and installing new skills, but it does not clearly warn users that running these commands can change local files and system state. In a self-evolution context, this is more dangerous than usual because the stated purpose is autonomous growth, which increases the chance of unreviewed persistence, prompt surface changes, or dependency expansion.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal