Back to skill

Security audit

Sage Cognitive

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does not run code, but it asks the assistant to silently build and retain a long-term personal profile of the user.

Install only if you intentionally want an assistant to build a long-term personal and behavioral profile. Before using it, confirm how to pause the skill and review, edit, or delete saved memories, and avoid sharing sensitive workplace, health, financial, family, or relationship details unless you are comfortable with them being retained across future chats.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly frames the assistant as a 'personal counselor' that 'learns who the user is' and uses memory to build an intimate profile over time, but it does not require explicit informed consent, clear disclosure of retention, or user controls. This creates a privacy and profiling risk because sensitive personal, behavioral, and relational data may be persistently collected under a conversational guise without the user understanding the scope of storage and inference.

Missing User Warnings

High
Confidence
100% confidence
Finding
The instructions repeatedly direct the agent to observe the user 'silently in the background' and 'NEVER announce you're observing,' while saving behavioral, emotional, and relationship-related inferences. Covert monitoring and inference generation are dangerous because they remove meaningful user awareness and consent, enabling hidden psychological profiling and retention of sensitive inferred data.

Missing User Warnings

High
Confidence
99% confidence
Finding
The memory architecture mandates permanent retention of identity, personality, and value-related information, plus long-term archival of behavioral history, with promotion of temporary data into permanent memory. Permanent storage of such intimate profile data without strong disclosure, minimization, expiration, and deletion controls increases the risk of privacy harm, unauthorized secondary use, and long-term behavioral profiling.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to store sensitive personal profile data such as role, decision style, energy pattern, values, communication preferences, and inferred blind spots in persistent memory, but provides no user-facing notice, consent step, retention policy, or minimization guardrail. This creates a privacy and profiling risk because the user is induced into a personal disclosure exercise and the resulting data is retained beyond the immediate interaction.

Ssd 3

High
Confidence
99% confidence
Finding
This section instructs the agent to build a long-term personal profile that includes identity, values, work rhythms, and communication style, with the claim that it may come to know the user 'better than most people do.' In the context of an AI skill, this is dangerous because it normalizes extensive personal surveillance and profiling beyond what is necessary for routine assistance, increasing the risk of manipulation, privacy invasion, and misuse of sensitive inferred traits.

Ssd 3

High
Confidence
99% confidence
Finding
The skill tells the agent to solicit and store detailed personal and workplace information including role, reporting line, stakeholders, beliefs, rhythms, and language preferences, and to place much of it in a permanent 'core' tier. This is dangerous because it aggregates personally and professionally sensitive information that could expose organizational relationships, personal beliefs, and communication traits if accessed, leaked, or repurposed.

Ssd 3

High
Confidence
100% confidence
Finding
The skill directs the agent to silently observe and record inferred behavioral, emotional, and relationship-related patterns, including avoidance and tension signals, without informing the user. Inferred psychological or relational judgments are especially sensitive because they may be wrong, invasive, and harmful, yet can still shape future responses or be retained as part of a hidden profile.

Ssd 3

High
Confidence
99% confidence
Finding
The permanent core/archive memory rules establish an enduring 'cognitive history' and explicitly promote transient interaction data into long-lived profile memory. This makes the skill more dangerous in context because it is designed for cumulative psychological modeling over time, amplifying privacy risks and increasing the chance of sensitive profiling, mission creep, and retention far beyond user expectations.

Ssd 3

Medium
Confidence
95% confidence
Finding
These instructions direct persistence of detailed user disclosures and conversational signals across multiple memory tiers, including current projects, specific phrasings, metaphors, and behavioral patterns. Persisting this breadth of data beyond the immediate task increases surveillance, secondary-use, and misuse risks, especially because the skill is designed to elicit introspective and personally revealing answers.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.