Back to skill

Security audit

Self Reflection

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local self-review logger, but users should be careful because it creates persistent reflection notes and its README points to an external CLI repository.

Install only if you want the agent to keep local self-review memory over time. Avoid logging secrets, credentials, private user data, or sensitive project details, and inspect the external GitHub CLI before symlinking or running it because that executable was not included in this reviewed package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The README explicitly instructs the agent to persist reflections and timer state to local files, but it does not warn that these reflections may contain sensitive operational details, prompts, errors, secrets, or user data. In an agent setting, 'mistakes' and 'fixes' can easily capture confidential context, and durable storage increases the chance of later disclosure, unintended reuse, or cross-task data leakage.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill is described in broad, generic terms such as 'continuous self-improvement' and is triggered regularly via heartbeat, which can cause the agent to invoke it in many situations beyond a narrowly defined scope. This increases the chance of unintended activation, unnecessary memory writes, and unreviewed reflection behavior becoming part of normal operation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.