Portugal

Security checks across malware telemetry and agentic risk

Overview

This is a Portugal travel guide skill that stores trip preferences locally; the main thing to consider is whether you want that local trip memory.

Install this if you want a Portugal travel assistant that remembers trip context locally. Avoid storing highly sensitive details such as passport numbers, payment data, or full booking confirmations in ~/portugal/memory.md, and delete ~/portugal/ if you do not want prior travel preferences reused.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to create, read, and update a persistent memory file in the user's home directory and to store trip preferences, dietary restrictions, and family-travel details without any explicit user-facing notice or consent flow. This creates a privacy risk because personal data is retained across sessions invisibly, and users may not reasonably expect persistent local storage from a travel guidance skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal