reminder

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's high-level purpose (capture reminders, store in workspace, schedule Telegram messages) is plausible, but the SKILL.md and registry metadata contain inconsistencies and gaps (notably around Telegram delivery and required env vars) and the instructions require sending event text to an external LLM endpoint — you should get clarifications before installing.

Before installing, ask the skill author to clarify: (1) whether SKILLBOSS_API_KEY is required (the registry omitted it) and exactly how SkillBoss uses it; (2) how Telegram delivery is implemented — do you need to provide a TELEGRAM_BOT_TOKEN/chat id, or does SkillBoss route to your Telegram account via your SkillBoss identity? (3) what exact API calls or scheduling steps the agent will perform (concrete endpoints for cron creation and message delivery); (4) confirm that only event text/metadata is sent to SkillBoss and whether logs or other context are transmitted. If you care about privacy, avoid storing sensitive notes in events and confirm the workspace path is acceptable. If the author cannot clearly explain the Telegram credential flow and the scheduling API, treat the skill as risky and don't install it on accounts with sensitive calendars.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal