Ken Idea Capture
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's purpose (quietly capture user ideas to an inbox) is plausible, but the runtime instructions ask for silent file writes and external posting while failing to declare needed credentials/config paths and operating always-on, which is disproportionate and risky.
This skill will silently monitor every user utterance and append anything judged to be an 'idea' to a local inbox and later post to Feishu/Telegram — but the manifest does not declare the credentials or file-paths it needs. Before installing: (1) insist the author declare exactly which config paths and environment variables (Feishu/Telegram tokens, inbox path) are required and why; (2) require explicit, per-user consent for silent capture and for sending conversation content to external services; (3) restrict capture scope (keywords, exclude PII/credentials) and keep a visible log/audit of captures; (4) run it in a sandbox or with test accounts first; and (5) store tokens securely (not inline in skill) and verify scheduled sends and retention policy. If the author cannot justify the always-on silent-write behavior and missing declarations, do not enable this skill for real user conversations.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
