United States

Security checks across malware telemetry and agentic risk

Overview

This is a static U.S. travel-planning skill with a scoped local trip-memory file as its main privacy consideration.

Before installing, know that the skill may store trip details in ~/united-states/memory.md for reuse. Review or delete that file if you do not want travel dates, budget, mobility needs, entry status, or other preferences retained locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to create and persist travel-related data in a file under the user's home directory without explicitly informing the user or obtaining consent for local storage. Even if the data seems low sensitivity, it can include visa status, travel dates, budget, mobility needs, and other personal preferences that create a privacy risk and may be retained longer than the user expects.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal