Back to skill

Security audit

Munger Observer

Security checks across malware telemetry and agentic risk

Overview

This instruction-only reflection skill reviews today's agent memory and session logs for a disclosed daily mental-model review, with no evidence of exfiltration, destructive behavior, or hidden execution.

Install this only if you are comfortable with the agent using today's memory and session logs to produce a private thinking review. Use explicit invocations when possible, and avoid optional daily scheduling unless you want recurring reviews of stored work context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description includes broad natural-language phrases like 'review my thinking', 'check for blind spots', and 'apply mental models' that could match ordinary user requests and invoke the skill unexpectedly. Because the skill then reads today's memory file and scans session logs, accidental invocation can cause unanticipated access to sensitive contextual data and produce outputs based on private history the user did not explicitly consent to use in that moment.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The process explicitly instructs the skill to read today's memory file and scan session logs, but the skill description does not warn users that these data sources will be accessed. This creates a transparency and consent problem: users may invoke what sounds like a harmless thinking-review tool without realizing it will inspect potentially sensitive historical records and synthesize them into output.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.