Back to skill

Security audit

Personal Knowledge Hub

Security checks across malware telemetry and agentic risk

Overview

This skill is a local personal-knowledge helper that organizes and searches supplied or sample notes without hidden network, credential, persistence, or destructive behavior.

This appears safe to install for organizing personal notes. Be aware that broad study or note-related prompts may activate it, and only connect or provide note sources you intend the skill to process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to match many generic note-taking, study, and summarization requests, which can cause the agent to invoke this skill outside its intended scope. Over-broad routing increases the chance of misapplication, accidental access to connected note stores, or interference with more appropriate skills that have tighter safety boundaries.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The Chinese trigger list includes very common phrases that can appear in ordinary educational or productivity conversations, making unintended invocation more likely for Chinese-language users. This ambiguity is risky because the skill is framed around personal knowledge access and organization, so false activation could lead to over-claiming capabilities or operating on connected personal data when the user's intent was more general.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.