喜悦成长能量

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only parenting conversation analysis skill; its sensitive child-data use is visible and purpose-aligned, but users should minimize and redact what they share.

Before using this skill, treat all child conversations, recordings, names, schools, locations, and family details as sensitive. Prefer redacted transcripts over raw audio, share only what is needed, confirm you are allowed to share recordings involving others, and ask the agent to omit or summarize the raw conversation if you do not want it preserved in the report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly invites users to submit highly sensitive child-related conversations and psychological observations, but it provides no notice about privacy risks, consent expectations, retention, or handling of personal data. In this context, the omission is significant because the content involves minors and inferred mental-state analysis, increasing the risk of oversharing sensitive information without informed user awareness.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill offers to process uploaded audio files for transcription without warning that recordings may contain highly sensitive personal, familial, and child-related information. Because users may upload raw voice recordings assuming convenience, the lack of explicit disclosure and minimization guidance can lead to unnecessary exposure of sensitive audio data and inferred psychological information.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly invites users to submit child conversation transcripts, recordings, and psychological observations, which are highly sensitive personal data, yet it provides no privacy notice, consent guidance, data minimization instructions, or retention boundaries. In this context, the omission is dangerous because the subject is a child and the output includes preserving the full raw conversation, increasing the risk of over-collection, secondary exposure, and unsafe handling of intimate family data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal