Greece

Security checks across malware telemetry and agentic risk

Overview

This Greece travel-planning skill is a local markdown guide that keeps trip preferences in a dedicated local folder and does not show evidence of hidden or unsafe behavior.

Install only if you are comfortable with the skill saving Greece trip preferences in ~/greece/memory.md. Review or delete that file if it includes travel dates, family details, mobility needs, budgets, or bookings you no longer want retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to create and read persistent files under the user's home directory (`~/greece/` and `~/greece/memory.md`) without any disclosure, consent, or explanation to the user. This creates a privacy and persistence risk because trip preferences and constraints are stored across sessions, and the agent may access prior data the user did not knowingly authorize it to retain or reuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal