Remind

Security checks across malware telemetry and agentic risk

Overview

This is a coherent reminder skill, with normal reminder-learning behavior but some privacy and consent considerations around inferred reminders.

Install this if you want an assistant that can infer and adapt reminders from your conversations. For sensitive commitments, prefer explicit reminder requests and periodically review or clear learned reminder preferences and inferred reminders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill’s activation logic depends on external files (`triggers.md` and `timing.md`) and vague concepts like 'remindable commitments' without defining enforceable boundaries in this file. That ambiguity can cause the agent to trigger reminders in unintended contexts, misclassify alerts/notifications as reminders, or over-collect behavioral signals while 'learning' from observation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The implicit trigger rules are broad and can match ordinary conversational statements like future plans, time mentions, or mild concern, causing the reminder skill to activate without clear user consent. In a reminder context, this creates a real risk of unintended data capture, autonomous reminder creation, and user-confusing behavior because the system is inferring durable tasks from casual speech.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal