Back to skill

Security audit

Poly Daily Reading

Security checks across malware telemetry and agentic risk

Overview

This skill fits its reading-list purpose, but it can delete personal Obsidian reading files during scheduled archiving without clear safeguards.

Review carefully before installing. Use it only if you are comfortable with writes to the specified Obsidian Daily Reading folder, Mission Control ingestion, and cleanup of archived source files. Prefer adding a dry-run or confirmation step, and change deletion to move files into a recoverable trash or archive-staging folder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs deletion of individual daily files and monthly archive files as part of weekly/yearly archiving, but provides no confirmation, dry-run mode, backup step, or scope validation. In an automated cron-driven skill operating on user files, this creates a real risk of unintended data loss from logic errors, bad date calculations, or path mistakes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.