Back to skill

Security audit

Penfield

Security checks across malware telemetry and agentic risk

Overview

Penfield is a disclosed persistent-memory skill, with real privacy considerations but no artifact-backed evidence of hidden or malicious behavior.

Install only if you want an agent memory service that can retain preferences, decisions, project context, checkpoints, and files across sessions and integrations. Do not save secrets, credentials, regulated personal data, confidential internal documents, or sensitive business information unless you have confirmed Penfield's retention, access, review, and deletion controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill encourages broad, discretionary storage of user preferences, discoveries, decisions, and other context without strong consent boundaries or minimization rules at the point of use. In a persistent memory skill, ambiguous guidance can lead agents to over-collect sensitive personal, organizational, or security-relevant data and retain it across sessions, increasing privacy and data governance risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This skill prominently advertises persistent cross-session memory, artifact storage, and connectivity to remote MCP/API services, but does not provide a clear upfront warning about what data leaves the local environment, how long it is retained, or what should never be stored. Because the tool is designed to capture and synchronize durable memory, users or agents may unintentionally send sensitive conversation content, internal documents, or personal data to an external service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.