Back to skill

Security audit

Org Memory Curator

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended for memory archiving, but it gives broad long-term retention authority over chats, notes, and project material without clear user consent or retention limits.

Install only if you are comfortable with the agent deciding what work notes, chats, and project context may be saved for future use. Prefer using it with explicit archive requests, sensitive-data review, and a clear way to inspect and delete stored memories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broadly phrased to trigger whenever an agent needs to decide whether information should be preserved in long-term memory. That wide activation scope can cause the skill to be invoked on many ordinary conversations or documents, increasing the chance of over-collection, unintended retention of sensitive data, and inappropriate writes into organizational memory.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The Chinese instruction says to use the skill whenever any agent needs to archive project progress, meeting notes, chats, clarifications, or markdown materials, without meaningful scope limits. In context, this makes the skill more dangerous because it handles high-volume, potentially sensitive sources and could become a default sink for organizational data even when archival appropriateness or authorization is unclear.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal