Time Capsule

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only helper for leaving future-facing project notes, with persistence risks disclosed and no executable or hidden behavior found.

Install only if you are comfortable with agents helping write persistent notes into your repository. Treat capsules as normal code changes: review them, avoid credentials or private data, include authorship/context, and remove or expire notes that become stale.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill's 'When to Invoke' section uses broad, subjective activation guidance such as 'after making a non-obvious decision' and 'when writing code you know will be confusing' rather than a tightly scoped trigger contract. In an agent environment, this can cause over-broad invocation and unintended activation on many coding tasks, increasing prompt-surface exposure and the chance that sensitive repository context is processed when not strictly necessary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal