Back to skill

Security audit

Morning Note

Security checks across malware telemetry and agentic risk

Overview

This skill creates investment morning reports and stores them in disclosed places, but users should understand the local file and IMA archive behavior before using it.

Install this if you are comfortable with investment summaries being saved in the workspace and potentially archived to IMA. Avoid including sensitive holdings, proprietary watchlists, or strategy notes unless you know who can access those files and notes, and prefer disabling or confirming archive behavior for scheduled or ambiguous runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Low
Confidence
86% confidence
Finding
The skill documentation adds a side effect beyond simple report generation by synchronizing content into an IMA knowledge-base note. This creates an additional data-write channel that may surprise users, persist potentially sensitive financial summaries in another system, and expand the blast radius if the skill is triggered unintentionally or with tainted content.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly states that generated morning reports are saved to disk and that IMA knowledge-base synchronization performs automatic archival, but it does not mention user consent, retention limits, or what data may be persisted. Because the skill processes portfolio, watchlist, and market-monitoring information, silent persistence can expose sensitive financial interests or behavior if the files are later accessed, synced, or retained unexpectedly.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary requests such as '早报', '今日概览', or 'morning note', increasing the chance of accidental activation. Because this skill performs file writes and later syncs content to a knowledge base, unintended triggering can cause unexpected data modification and unnecessary external queries.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises report generation but does not clearly warn users that it will write files to the workspace and synchronize notes to another system. Hidden state-changing behavior is risky because users may invoke what appears to be a read-only summarization task and unknowingly cause persistent storage of financial content.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.