Japan

Security checks across malware telemetry and agentic risk

Overview

This Japan travel guide is coherent and only stores trip preferences locally, with no hidden network access or destructive behavior found.

Install if you want a Japan travel-planning helper with local trip memory. Before using it, know that preferences and trip details may be saved in ~/japan/memory.md; avoid storing sensitive confirmation numbers or personal details there unless you are comfortable with local persistence, and delete or edit that file when you no longer want the memory retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to create and update a persistent file in the user's home directory without any explicit user-facing disclosure, consent flow, or explanation of what data will be stored. Even though the content is travel-planning context rather than obviously sensitive secrets, it can still include personal preferences, budget, mobility constraints, and travel dates, creating privacy and persistence risks the user may not expect.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal