reminder
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's high-level purpose (capture reminders, store in workspace, schedule Telegram messages) is plausible, but the SKILL.md and registry metadata contain inconsistencies and gaps (notably around Telegram delivery and required env vars) and the instructions require sending event text to an external LLM endpoint — you should get clarifications before installing.
Before installing, ask the skill author to clarify: (1) whether SKILLBOSS_API_KEY is required (the registry omitted it) and exactly how SkillBoss uses it; (2) how Telegram delivery is implemented — do you need to provide a TELEGRAM_BOT_TOKEN/chat id, or does SkillBoss route to your Telegram account via your SkillBoss identity? (3) what exact API calls or scheduling steps the agent will perform (concrete endpoints for cron creation and message delivery); (4) confirm that only event text/metadata is sent to SkillBoss and whether logs or other context are transmitted. If you care about privacy, avoid storing sensitive notes in events and confirm the workspace path is acceptable. If the author cannot clearly explain the Telegram credential flow and the scheduling API, treat the skill as risky and don't install it on accounts with sensitive calendars.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
