Back to skill

Security audit

ia-reflect

Security checks across malware telemetry and agentic risk

Overview

This reflection skill has persistent memory features, but they are tied to its retrospective purpose and mostly require user confirmation before writing.

Before installing, be aware that this skill can save approved session lessons and explicit remember: items into project memory. Avoid approving sensitive data, secrets, private customer details, or temporary preferences for persistence, and review proposed skill diffs before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a retrospective/audit tool, but it instructs the agent to persist session-derived items into project memory files. That expands behavior from analysis into state-changing data retention, which can store sensitive or incorrect user/session information without the persistence action being clearly disclosed in the primary skill description.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The `remember:` mechanism causes direct persistence of user-provided content, but that capability is not clearly disclosed in the top-level description. A user could invoke a reflection workflow expecting ephemeral analysis while actually triggering durable storage of text that may include sensitive preferences, credentials, or project details.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Creating and modifying persistent memory files is broader than what is necessary for a session retrospective skill. This unjustified capability increases the blast radius of the skill by allowing durable state changes based on conversational content, creating privacy, integrity, and prompt-injection persistence risks.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill goes beyond retrospective analysis by directing the agent to propose and potentially apply edits to other skills. That broadens authority from auditing into modifying system behavior, which can be abused to propagate flawed guidance or persistent changes across the environment.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs filesystem writes to persistent memory without a prominent user-facing warning at the point the capability is introduced. Hidden or under-disclosed side effects undermine informed consent and can lead to unintended retention of sensitive, stale, or adversarially induced content.

Missing User Warnings

Low
Confidence
82% confidence
Finding
The optional hook describes writing user-derived data into a queue file for later processing, but it does not clearly warn about this persistent capture. Although framed as optional, it normalizes silent collection of user corrections and preferences into durable storage, which creates privacy and consent concerns.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.