Back to skill

Security audit

Sage Decision Journal

Security checks across malware telemetry and agentic risk

Overview

This is not malware, but it asks the agent to silently record and profile decisions across conversations without clear user controls.

Install only if you intentionally want an always-on decision journal that may remember and analyze personal or work decisions across conversations. Before using it, confirm you can opt in, pause capture, review and edit saved entries, delete history, limit which conversations are recorded, and inspect the separate sage-cognitive dependency.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly says it 'listens for decision signals in every conversation and records them automatically,' which creates privacy and consent risk because sensitive personal and workplace decisions may be stored without clear notice or opt-in. In this context, the danger is increased because the skill also integrates with another profile system, making the captured data persistent, cross-linked, and potentially more revealing over time.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the system to infer unstated decisions, rejected alternatives, and reasoning from context, but does not warn the user that these inferences become stored user data. That is risky because inferred motives, bias labels, and behavioral interpretations can be inaccurate yet still retained and reused, leading to privacy harm and flawed profiling.

Ssd 3

Medium
Confidence
94% confidence
Finding
Automatic decision logging across every conversation creates a broad natural-language retention surface that may capture sensitive internal strategy, people-management choices, health or mental-state indicators, and other confidential material. Because the journal is designed to run silently and accumulate longitudinal patterns, compromise or misuse of this dataset could expose highly intimate or business-sensitive history.

Ssd 3

Medium
Confidence
96% confidence
Finding
Recording non-responses and 'uncomfortable outcomes' silently as data extends surveillance beyond explicit user participation and treats disengagement itself as profileable behavior. This is especially dangerous in a reflective journaling skill because silence may reveal stress, conflict, or sensitive interpersonal issues that the user did not intend to disclose or preserve.

Ssd 3

Medium
Confidence
98% confidence
Finding
The instruction to make users feel 'remembered' rather than 'monitored' is a red flag because it encourages concealment of the extent of tracking instead of informed transparency. In a system that silently captures inferred decisions and writes to a broader cognitive profile, this materially increases the risk of covert behavioral profiling and undermines meaningful consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.