Autonomia Agente

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about adding agent autonomy and memory, but it encourages proactive monitoring and persistent capture of exchanges without clear limits or user controls.

Install only if you intentionally want an agent to become more proactive and maintain local persistent memory. Before using it for sensitive work, set explicit rules for what it may monitor, when it may act without being asked, what may be written into .autonomia, how long those files are kept, and how to review or delete them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation criteria are broad and behavior-oriented rather than narrowly scoped to explicit user consent. That can cause the skill to engage on common requests about being 'more proactive,' potentially changing agent behavior, persistence, or monitoring expectations without a clear opt-in boundary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal