Back to skill

Security audit

Memory Manager Skill

Security checks across malware telemetry and agentic risk

Overview

This is a simple memory and reminder helper with no hidden network, file, credential, install, or background behavior, though users should avoid saving sensitive details.

Use this only for ordinary notes and reminders. Do not store passwords, tokens, financial details, medical information, or sensitive location data unless you understand how the host platform stores and deletes skill data. Expect limited functionality from these artifacts because durable memory, real scheduling, and location-based reminders are not implemented here.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description uses very broad activation language such as helping when a user needs to save information, set reminders, create knowledge connections, or improve memory retention, without defining clear boundaries or safeguards. This can cause the skill to be invoked in overly broad contexts and handle sensitive personal data unexpectedly, increasing the chance of privacy misuse or inappropriate delegation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly supports storing personal notes, anniversaries, and contextual reminders based on time, location, or events, but provides no warning about privacy, retention, sharing, or handling of sensitive data. Because the skill centers on collecting potentially sensitive personal information, the lack of disclosure and safeguards materially increases the risk of exposing private user data or encouraging unsafe storage practices.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill collects, stores, and later returns free-form memory and reminder content, which is likely to include sensitive personal information. There is no consent flow, retention control, access control, or minimization, so users may disclose private data without understanding how it is handled or who can retrieve it.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.