India

Security checks across malware telemetry and agentic risk

Overview

This India travel-planning skill is coherent and stores trip preferences locally, with no evidence of network access, executable code, or hidden behavior.

Install only if you are comfortable with India trip context being saved in ~/india/memory.md for reuse. Avoid storing passport, payment, or exact sensitive itinerary details unless you intentionally choose to, and review or delete the local memory file when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to persist user travel preferences to `~/india/memory.md` without telling the user that their data will be stored. Even though the data is framed as trip-planning context, it can include potentially sensitive personal information such as travel dates, group composition, mobility needs, and preferences, creating a privacy and retention risk through undisclosed storage.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction to keep updating `~/india/memory.md` with route, dates, group type, comfort level, and likes/dislikes establishes ongoing accumulation of personal trip data without any privacy notice or retention controls. Repeated updates increase risk because the file can become a detailed profile of the user's plans and constraints, which could be exposed, misused, or retained longer than expected.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal