Back to skill

Security audit

Tiny Builder

Security checks across malware telemetry and agentic risk

Overview

Tiny Builder is a coherent kids' HTML-building skill, but it automatically stores detailed child activity and behavior logs without clear controls.

Review before installing for a child. Use it only with parent supervision, keep ~/tiny-builder private, avoid children entering personal details, review gui.new links before sharing, and periodically delete or trim parent-log.md and projects/build-log.md if you do not want long-term child activity records retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to persist detailed child session summaries, including what the child asked for, how they behaved, and possible emotional/frustration flags, into a parent-readable local log. That exceeds the minimum data needed to build HTML projects and creates unnecessary retention of potentially sensitive child interaction data, especially given the child-focused context.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The skill adds educational tagging and skill-practice profiling to projects, which creates an additional layer of behavioral/learning inference about a child beyond the core task of building simple apps. While lower risk than explicit personal data collection, it still increases data sensitivity and expands the system's role into profiling without a clear necessity.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly describes automatic logging of children's requests, projects, and behavioral summaries to a local markdown file, but does not mention parental notice, consent, retention limits, or access controls. Because the skill is aimed at children ages 5–8, this creates a real privacy risk: sensitive child activity data may be stored in plain text and later exposed to other local users, backups, sync tools, or accidental sharing.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The logging instructions tell the agent to write session summaries and flags about the child to a local file, but they do not require informing the user or parent at interaction time that these details are being recorded. This lack of notice is especially problematic for a child-oriented skill because sensitive behavioral context may be retained without clear transparency.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill directs the agent to save local backups and maintain project/build logs but does not explicitly warn that user-created content will be written to disk. Even if the content is benign, silent storage of a child's creations and activity history reduces transparency and can surprise users or parents.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes a child-directed persona ('Kid Mode Agent') and instructs the agent to interact in a way tailored to children without any opt-in, age check, or user-controlled mode selection. This can cause misclassification of users, inappropriate infantilization, and heightened safety risk because a child-oriented framing may encourage overtrust or make the agent unsuitable for general audiences by default.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The instruction to always use simplified speech ('I talk like you talk') imposes a fixed language-style policy without checking user preference, age, or comprehension needs. In context this is less severe than direct security exploitation, but it can still degrade user autonomy, produce patronizing responses for non-children, and reinforce the broader problem of treating all users as children by default.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document explicitly states that a child's building sessions are logged automatically, including timestamps, project details, prompts, and behavioral summaries, but provides no notice about consent, retention, access controls, or how this data is handled. Because the subject is a minor, the privacy sensitivity is elevated and the absence of privacy guidance increases the risk of inappropriate collection, storage, or disclosure of personal data.

Ssd 3

Medium
Confidence
94% confidence
Finding
The session log example shows retention of natural-language child requests and narrative summaries of behavior in a human-readable file, which increases the chance of sensitive information leakage compared with structured, minimal telemetry. In this context, the data concerns young children, making even local plain-text retention more sensitive and more likely to violate privacy expectations if the file is copied, synced, indexed, or accessed by others on the device.

Ssd 3

Medium
Confidence
95% confidence
Finding
The required parent log creates a deliberate retention and disclosure path for a child's requests, session details, and behavioral notes in natural language. Because this data is stored and intended for third-party review, it increases privacy risk and the chance of overcollection, especially when flags include frustration, inappropriate requests, or out-of-scope help-seeking.

Ssd 3

Low
Confidence
88% confidence
Finding
The build-log feature requires ongoing persistence of the child's project history over time, creating a longitudinal activity record. While less sensitive than the parent dashboard narrative log, it still retains user activity beyond immediate functionality and can accumulate behavioral metadata.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.