Back to skill

Security audit

Fulcra Memory

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Fulcra memory-sync helper, with expected remote uploads and a limited inbox cleanup step that users should supervise.

Install this only if you intend to use Fulcra as an external memory store for agent progress and summaries. Review what the agent writes before upload, avoid secrets and private reasoning, and ensure inbox messages are archived correctly before deleting originals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs a remote delete operation against an agent inbox, which exceeds the narrowly stated purpose of progress reporting and memory syncing. Even though it says to archive first, this still introduces destructive capability into a reference that may be invoked automatically or without sufficient operator review, increasing the risk of accidental or unauthorized data loss.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The documented capability to delete files from a remote inbox is not clearly necessary for the skill's declared function of memory sync and progress reporting. Unjustified destructive scope is dangerous because it broadens what the agent may do in Fulcra and can be abused or triggered inappropriately to remove evidence, user submissions, or pending work items.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill tells the agent to delete inbox files after archiving but provides no prominent warning about permanence, failure modes, or the need to confirm archive integrity first. In an operational setting, this can lead to silent loss of user-provided content if the upload path is wrong, the archive upload fails partially, or the wrong inbox item is targeted.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.