Back to skill

Security audit

inner-life

Security checks across malware telemetry and agentic risk

Overview

This journaling skill is coherent about its purpose, but it can retain conversation details and inject summaries into future sessions without clear consent, limits, or deletion controls.

Install only if you deliberately want the agent to keep a dated journal about interactions and carry a short summary into future sessions. Avoid using it around secrets, personal data, regulated information, or shared environments unless you first add clear rules for consent, redaction, retention, and deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The top-level description is broad enough that the skill could be invoked in many loosely related situations involving continuity, logging, or reflection. Overbroad activation increases the chance the agent will start persistent journaling or state carry-forward when the user did not clearly request it, which can indirectly cause privacy or retention issues.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The 'When to Use' triggers include vague conditions like 'something happened worth recording' and 'what's been going on,' which leave activation to broad agent judgment. In a skill that writes persistent state, ambiguous triggers are risky because they can capture user content or agent-generated interpretations without a clear opt-in boundary.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explains that summaries are written into native memory and injected into every session, but it does not present this as a user-facing warning or consent requirement. That omission is dangerous because users may share sensitive content without realizing it can persist and influence unrelated future interactions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to read, write, refresh, and prune persisted files across sessions without any user confirmation or safety boundary around modifying stored data. In this skill’s context, persistent state is the core feature, which makes the behavior intentional, but it still creates a real risk of silent data modification, retention, or deletion that the user may not expect.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to persist dated facts about user conversations and other events, including tone and unresolved questions, without any user-facing notice, consent, or data-minimization boundary. In the context of an 'inner-life' skill designed to carry state across sessions, this creates a meaningful privacy risk because interaction details may be retained longer than the user expects and can influence future behavior.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to preserve session-derived state across sessions and have Hermes inject a summary into future system prompts. This creates a real data retention and disclosure risk because natural-language summaries may contain sensitive user information, inferred traits, or context that becomes broadly available in later sessions beyond the original purpose.

Ssd 3

High
Confidence
98% confidence
Finding
Writing dated summaries of the day into native memory that are injected into every future session materially expands the exposure surface of prior-session content. If the summary includes sensitive details, those details can leak into unrelated tasks, shape future model behavior, or be disclosed to later users sharing the environment.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill encourages recording 'a conversation, a failure, a thing that caught attention,' which naturally invites storing user-provided content and agent interpretations in persistent logs. Without privacy boundaries, this can capture sensitive or regulated information and retain it beyond user expectations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.