Wardrobe

Security checks across malware telemetry and agentic risk

Overview

This is a local wardrobe organizer skill with disclosed file storage and no evidence of hidden code, credential access, networking, or destructive behavior.

Install this if you want a local file-based wardrobe catalog. Before using it, confirm where the folder should be created and be selective about storing clothing photos, prices, wear logs, wishlist items, and donation or tax notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough to activate on ordinary clothing-related conversation, which can cause the agent to enter this skill unexpectedly. In context, that can lead to unsolicited behavior such as steering the user into wardrobe management workflows or preparing to create local state, increasing the chance of surprise actions and privacy-invasive data collection around personal belongings and photos.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs creation of a local workspace directory in the user's home folder without any user-facing disclosure or consent flow. Even though the directory itself is not inherently dangerous, silent filesystem modification violates the principle of least surprise and may lead to unintended storage of sensitive wardrobe data, including photos, purchase history, and donation/tax-related records.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal