Back to skill

Security audit

Personal Os Framework

Security checks across malware telemetry and agentic risk

Overview

This is a coherent personal knowledge-base skill, but it asks an AI to proactively read and update persistent personal files without enough user-control or privacy boundaries.

Install only if you intentionally want an AI-maintained personal knowledge base. Keep it in a dedicated folder, avoid secrets or highly sensitive information, require review of proposed file changes before writes, use backups or version control, and do not enable scheduled maintenance unless you explicitly approve what it can read and change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README explicitly encourages an AI to continuously read, record, maintain, and proactively act on a user's personal knowledge base, but it does not warn about privacy, consent, retention, or sensitive-data exposure. In a skill centered on a 'second brain,' this omission is material because users may place highly sensitive personal or professional information into the system without understanding the data-handling risks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly positions the AI to read and maintain a user's personal operating system, which implies access to and modification of user files without any built-in safeguard language about confirmation, scope limits, or data sensitivity. In a personal knowledge-management context, silent or habitual file writes can lead to unintended data corruption, privacy exposure, or inaccurate records being propagated across the system.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The instruction to 'read the personal-os after each conversation' and 'update relevant files' encourages automatic persistence of conversational content into core files, but provides no consent, validation, or change-control mechanism. In this context, the danger is amplified because the files are described as canonical records of decisions, tasks, and state, so mistaken or overly aggressive updates can overwrite truth, leak sensitive content, or create durable false records.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document explicitly states that the AI should not wait for commands and should act proactively after reading and updating the user's personal system. In a skill centered on persistent memory and ongoing collaboration, this encourages autonomous modification of user data or workflows without clearly defined consent boundaries, approval gates, or integrity safeguards, increasing the risk of unintended or unauthorized actions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document instructs AI collaborators to read the personal system after each conversation and update relevant files, while also stating that the AI should act proactively rather than waiting for commands. That creates an unsafe autonomy pattern: an agent may access and modify user data or local files without explicit per-action consent, increasing the risk of privacy leakage, unintended file changes, and destructive or incorrect state updates.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The prompt explicitly tells the AI to create project structure and update repository files like STATE.md and TODO.md without instructing it to obtain a confirmation before modifying local data. In an agentic environment with file-write capabilities, this can lead to unintended file creation or changes, especially if the user copies prompts without understanding the side effects.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
These prompts direct the AI to write review files and route captured notes into folders such as Chronicle/reviews, Knowledge, and Inbox, again without warning the user that files may be created or sensitive notes may be stored in persistent locations. In a personal knowledge-management skill, this increases the chance of unintended persistence, misclassification, and silent modification of user data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The quickstart explicitly instructs the AI to write to and update local files such as DECISIONS.md, STATE.md, and TODO.md, but it does not include guardrails around user confirmation, scope limitation, or backup/review before modification. In an AI skill whose purpose is ongoing maintenance of a personal knowledge system, normalizing unattended file edits increases the chance of unintended data corruption, overwrites, or privacy-impacting changes if the agent misinterprets user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide explicitly instructs the AI to read and modify multiple user files after each conversation, but it provides no guardrails around consent, confirmation, scope limits, or change review. In a personal knowledge-management skill, this creates a real risk of unintended or excessive file modifications, silent state drift, and corruption of user-maintained records if the agent acts on ambiguous conversational context.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The language "should not wait for commands" and "acts proactively" encourages autonomous behavior that can change user data or workflow state without an explicit trigger. In this skill's context, that is especially risky because the entire framework is designed around persistent memory and ongoing updates, so unchecked autonomy can amplify mistakes across multiple files and over time.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.