Back to skill

Security audit

Mindfulness Meditation

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only meditation skill with disclosed local logs and reminders that fit its stated purpose.

Safe to install based on the inspected artifacts. Use specific meditation prompts to avoid accidental activation, and treat notes, reminders, and exported logs as private wellness data, especially on shared or synced devices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase 'be present' is broad, generic language that can easily occur in ordinary conversation unrelated to meditation. This can cause unintended skill activation, leading to surprising behavior and collection/display of meditation-related data in contexts where the user did not explicitly invoke the skill.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill describes storing session history, personal notes, reminders, and exporting practice data, but it does not warn users that this information may be sensitive wellness data. Even if data stays local, users may underestimate privacy risks from shared devices, backups, screenshots, or exported files containing reflective notes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.