Time Management

Security checks across malware telemetry and agentic risk

Overview

This is a local time-planning skill whose memory use is disclosed and proportionate, with no executable code or network behavior found.

Install only if you are comfortable with the agent keeping local notes about your schedule preferences, focus times, weekly priorities, and commitments in ~/time-management/. Choose an only-when-asked activation style if you do not want proactive time-management prompts, and delete that folder to remove stored planning memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The setup instructs the agent to 'Start helping naturally' whenever the skill directory is missing or empty, without requiring a clear user opt-in for this specific skill. In a conversational assistant, vague activation behavior can cause the skill to engage on ordinary discussion of time, schedules, or tasks, leading to unintended collection of personal workflow details and unexpected behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The proposed activation prompt covers very common topics like 'your schedule or tasks,' which are likely to appear in normal conversation unrelated to wanting this skill enabled. That overlap increases the chance of accidental invocation, making the assistant steer conversations and potentially persist user information without meaningful consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs the agent to save a user preference in persistent storage but does not instruct it to clearly notify the user that data will be retained. Persisting behavioral preferences without transparent disclosure undermines user consent and can expose sensitive patterns about routines, work habits, and personal commitments over time.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The list of items to save includes peak energy hours, meeting constraints, planning preferences, and commitments, all of which can reveal sensitive personal and professional patterns. Because the skill description and flow do not warn users that these details will be persisted, the context makes the issue more concerning: time-management conversations routinely involve intimate daily routines and work obligations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal