Finland

Security checks across malware telemetry and agentic risk

Overview

This Finland travel-planning skill stores trip preferences locally for reuse, but its behavior is disclosed, narrow, and aligned with its purpose.

Safe to install for normal Finland trip planning. Be aware it may create and reuse ~/finland/memory.md, so avoid storing passport numbers, identity documents, payment details, or other highly sensitive information there; review or delete that file if you no longer want the trip context retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to create and update a persistent local memory file containing user travel preferences, constraints, and potentially sensitive context without any notice, consent, retention limits, or access controls. Even though the data is travel-related rather than highly regulated financial data, it can still reveal behavioral patterns, family status, mobility needs, dietary restrictions, and future travel plans, making this a real privacy and data-handling issue.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal