Back to skill

Security audit

Session-logs

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims by helping an agent search its own local session logs, but users should treat those logs as potentially private.

Install only if you are comfortable letting the agent search older local conversation logs. When using it, ask for narrow searches by date, topic, or session, and avoid requesting raw transcript output when summaries or redacted results are enough.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill explicitly instructs the agent to search complete prior conversation history stored in session logs, but it provides no warning, constraint, or consent check around sensitive data exposure. Because session logs can contain credentials, personal data, internal reasoning artifacts, and unrelated prior-user content, normalizing unrestricted log access increases the chance of privacy violations and cross-session data leakage.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.