Back to skill

Security audit

fulcra-tracking

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Fulcra tracking helper, but users should be careful with sensitive personal data and confirm deletions.

Install only if you want an agent to help create Fulcra schemas and send selected tracking data to your Fulcra account. Treat health, location, messaging, and prior-memory-based suggestions as sensitive: opt in deliberately, keep the tracked fields minimal, and ask the agent to show exact record IDs before deleting or correcting stored data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The deletion workflow tells the agent to delete records as part of correction handling but does not require an explicit user confirmation immediately before destructive action. In a tracking skill that manages user data remotely, this creates a realistic risk of accidental or misunderstood record deletion, especially if the agent misidentifies the target record or the user intended only to edit, not erase, prior data.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The reference content encourages combining sensitive behavioral and personal data sources such as messaging history, health data, GPS, media consumption, and subjective check-ins, but provides no accompanying privacy notice, consent guidance, minimization advice, or caution about sensitive inferences. In a skill that records annotations and visibility metrics, this can normalize broad collection of highly sensitive data and lead to overcollection, unexpected profiling, or privacy harm if adopted without explicit user understanding.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The file instructs the agent to tailor suggestions using information from USER.md, MEMORY.md, and previous chats without telling the user that prior stored context may be used for personalization. While this is less severe than direct collection of health or location data, it still creates a transparency and consent issue because personalization may rely on remembered or local data the user does not expect to be consulted in this interaction.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.