Dominican Republic

Security checks across malware telemetry and agentic risk

Overview

This travel-planning skill is coherent and scoped, with the main privacy consideration being a local saved trip-memory file.

Safe to install if you are comfortable with a local memory file for Dominican Republic trip planning. Avoid storing passport numbers, payment details, or other sensitive identifiers, and review or delete ~/dominican-republic/memory.md when the trip is over or if the details become sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs creation of a persistent memory file and storage of user travel preferences and trip details, but provides no user notice, consent mechanism, retention limit, or guidance on handling potentially sensitive itinerary data. Persistent storage of travel windows, airports, family setup, and mobility needs can expose privacy-sensitive information and create unnecessary long-term profiling if accessed by other skills, users, or processes.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill tells the agent to read and reuse a persistent memory file for returning users without disclosing that ongoing access to previously saved travel data will occur. Silent reuse of stored profile and trip information undermines user expectations, can lead to over-collection across sessions, and may reveal past travel intentions or personal constraints without fresh permission.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal