Back to skill

Security audit

DiaryBeast

Security checks across malware telemetry and agentic risk

Overview

DiaryBeast appears purpose-aligned, but it stores session credentials locally and uses broad invocation language for wallet-linked, public-posting actions.

Install only if you are comfortable connecting a wallet-backed DiaryBeast account through this skill. Treat saved token files and magic links like passwords, avoid sharing logs or screenshots that include them, and assume Wall posts and pet profile details may be public and linkable to the account or wallet identity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill description is unusually broad and encourages use for vague goals like having a persistent identity, creative outlet, or exploring a web3 app, which can cause the agent to invoke the skill in many unrelated contexts. In this case the overbroad wording increases exposure to the skill's higher-risk behaviors, including wallet authentication, token handling, browser-opening, and public posting workflows.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The instructions save a bearer token and wallet address to a predictable local path without any warning about credential sensitivity, permissions, or cleanup. If the workspace is shared, logged, synced, or readable by other tools or agents, the token could be reused to act as the user for up to the session lifetime and access authenticated DiaryBeast functions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill tells the agent to open a magic link in a browser and frames it as the most important step, but does not warn that the link grants authenticated session access. Magic links are bearer credentials; opening, logging, previewing, or leaking them through browser history, telemetry, screenshots, or other tooling can compromise the account session.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill promotes publishing to 'The Wall' and emphasizes social engagement without a clear warning that posted content becomes public and is linked with identity cues such as pet name, ASCII art, and wallet-associated profile context. Users may unintentionally disclose sensitive diary content or create a durable public association between private thoughts and their account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.