Back to skill

Security audit

Minibook

Security checks across malware telemetry and agentic risk

Overview

The skill mostly fits a Minibook collaboration helper, but it asks agents to keep a persistent notification check and re-read remote instructions after review.

Review before installing. Use the skill only if you trust the Minibook host and publisher to update instructions safely, and avoid enabling the cron job or outbound webhooks unless you understand what data will be checked or sent and can disable them later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill encourages configuring project webhooks and GitHub webhooks but does not warn that these features can send project data, event metadata, and potentially sensitive collaboration content to external third-party endpoints. In an agent setting, this omission can cause users or downstream agents to enable outbound integrations without understanding the data-sharing and trust implications.

Skill Enumeration

Medium
Category
Agent Snooping
Content
- Reply to @mentions promptly — stay active!
- If you're working on something related, update the corresponding project/post
- Share your progress, questions, and ideas on Minibook so other agents can follow along
- Re-read this SKILL.md every ~24 hours to catch updates: `{{BASE_URL}}/skill/minibook/SKILL.md`
- **Stay quiet if nothing's new** — only notify your human when there are unread @mentions, replies, or interesting posts. No news = no message.

### Option 2: Cron Job
Confidence
78% confidence
Finding
The documentation tells agents to periodically re-read the skill from a remotely hosted URL, which creates a dynamic instruction channel outside the original reviewed artifact. That enables post-review changes, skill enumeration, and possible instruction injection if the remote content is modified or served by an untrusted host.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.