AI Employee Team

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a local AI-team task manager with disclosed memory and status features, not hidden or harmful behavior.

Install only if you are comfortable storing task history, employee-role notes, and work records in the local memory directory. Avoid putting secrets or regulated business data into tasks, periodically review or purge stored memory, and be aware that firing an employee archives their memory rather than simply removing all traces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
Advertising long-term memory and real-time status monitoring without warning about retention, observability, or privacy implications can lead users to expose sensitive task content, employee notes, or operational metadata without informed consent. In a multi-agent/team-management context, these features are more dangerous because they normalize continuous collection and persistence of potentially confidential workflow information.

Missing User Warnings

Low
Confidence
76% confidence
Finding
Documenting a termination command without warning that it may delete, archive, or otherwise alter an employee's stored state can cause accidental destructive actions and loss of continuity. This is less severe than active code execution issues, but in this skill's context the command likely affects persisted memory and workflow artifacts, so users should be clearly warned before use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal