Back to skill

Security audit

agent-inner-life

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local journaling and continuity tool, with real persistence and memory-reuse risks that are mostly explained and purpose-aligned.

Install only if you want an agent to keep a durable local record of how work is going and to carry a short summary into future sessions. Avoid it on shared hosts unless access is controlled, and manually delete inner-life/ plus clear the memory summary if you want the record removed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to persist reflections derived from `inner-life/state.md` into dated files and to copy selected content into `Sparks`, which is then injected into later sessions. Even though the document warns against writing about the user personally, it still creates durable storage and cross-session propagation of internal state-derived content without any explicit consent, retention limit, or privacy warning. In this skill context, that increases risk because the memory is specifically designed to influence future runs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is triggered by broad, ordinary-language prompts such as asking how things have been going or what is still open. That creates an overbroad invocation surface where routine conversation could unintentionally activate recall and disclose journal or state data, especially because this mode reads from a sensitive local record. The surrounding content partially mitigates this by warning not to assume the asker is authorized, but it does not define an enforcement mechanism.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.