Dream Cycle

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly harmful, but it asks for silent scheduled memory/workspace cleanup without enough limits or review controls.

Review carefully before installing. Use the audit and brief scripts manually first, and only enable scheduled runs after adding clear path limits, change logs, backups, approval for edits, and an easy way to disable the cron jobs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation text is broad enough to match generic requests like memory maintenance or reducing bloat, which could cause the skill to run in contexts the user did not specifically intend. Because the skill describes scheduled and potentially silent review/optimization of memory and workspace files, overbroad triggering increases the risk of unintended autonomous file changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description promotes a nightly process that 'cleans up bloated workspace files' and later states the agent 'silently reviews memories, optimizes files,' but it does not clearly warn users that files may be modified automatically without interactive confirmation. In this context, silent modification of memory/workspace content is dangerous because it can alter or remove important data, introduce hard-to-audit changes, and surprise users who expected only summarization.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal