Back to skill

Security audit

Operational Heartbeat

Security checks across malware telemetry and agentic risk

Overview

This is a small health-check skill that may create one dated local memory file and inspect cron status, with no hidden scripts or network behavior found.

Install only if you want a scheduled operational heartbeat that can create today’s memory file and inspect cron health. Before running it automatically, confirm the working directory and memory path, and avoid pointing it at sensitive notes unless that is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to create `memory/YYYY-MM-DD.md` if it is missing, but the description does not warn users that the skill may create or modify files. This is a real transparency and consent issue: even though the action is limited and appears operationally benign, undisclosed file creation can surprise operators, affect audit expectations, and be unsafe in automated scheduled execution contexts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.