Eternal Daily Briefing

Security checks across malware telemetry and agentic risk

Overview

This daily-briefing skill appears purpose-aligned, but it can gather local personal context and external live data from broad trigger phrases that may fire unintentionally.

Install only if you are comfortable with the skill reading local task/event or briefing files and using external data providers. Prefer configuring it to run only on explicit commands, and review any scheduler, stored paths, and provider settings before enabling automatic daily use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad and overlap with normal conversation such as asking for an update or what is happening today. This increases the chance of accidental invocation, which is risky here because the skill aggregates personal files and external content and may disclose or process sensitive information when the user did not explicitly intend to run it.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill description and usage guidance do not clearly warn that it pulls data from third-party network sources and local personal files like tasks and events. Without this disclosure, users may unknowingly expose private context or rely on externally sourced content without understanding the privacy and trust implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal