Family Memory Timeline
Security checks across malware telemetry and agentic risk
Overview
The skill's code and instructions are internally consistent with its stated purpose (generating timeline stories from supplied photo paths and conversation text); it does not request credentials, make network calls, or perform file I/O in the included code.
The skill appears to do what it says: synthesize stories from media metadata and conversation text using a simulated analysis engine. Before installing or using it: (1) review the repository (clawhub.json/skill.json point to a GitHub repo) to confirm source authenticity; (2) do not pass sensitive files or system-wide paths unless you trust the running agent—the skill expects media paths but the included code does not itself read files; if an agent collects files for you it may read arbitrary local data; (3) test the skill in a sandbox with non-sensitive sample data (scripts/test-stub.js is provided for this); (4) confirm the deployment environment prevents unwanted filesystem/network access if you expect strict privacy. Overall this skill is internally coherent and low-risk given the provided sources, but exercise normal caution when giving any agent access to local files or when supplying actual family photos/conversations.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
