Ken Idea Capture

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's purpose (quietly capture user ideas to an inbox) is plausible, but the runtime instructions ask for silent file writes and external posting while failing to declare needed credentials/config paths and operating always-on, which is disproportionate and risky.

This skill will silently monitor every user utterance and append anything judged to be an 'idea' to a local inbox and later post to Feishu/Telegram — but the manifest does not declare the credentials or file-paths it needs. Before installing: (1) insist the author declare exactly which config paths and environment variables (Feishu/Telegram tokens, inbox path) are required and why; (2) require explicit, per-user consent for silent capture and for sending conversation content to external services; (3) restrict capture scope (keywords, exclude PII/credentials) and keep a visible log/audit of captures; (4) run it in a sandbox or with test accounts first; and (5) store tokens securely (not inline in skill) and verify scheduled sends and retention policy. If the author cannot justify the always-on silent-write behavior and missing declarations, do not enable this skill for real user conversations.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal