Historical Data Manager

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal construction-data migration skill, with the main caution that it can read user-selected local archives and legacy database files.

Install this only if you want an agent to process local construction archives. Use a specific archive folder, verify spreadsheet/database paths before processing, avoid unrelated private directories, and review export filenames before allowing writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
90% confidence
Finding
The manifest description is very broad and does not clearly constrain when the skill should be invoked or what actions are out of scope. In agent ecosystems, overly general descriptions can cause inappropriate routing or over-invocation, which may expose filesystem-capable skills to data they were not intended to process.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal