Skill Experience Layer

Security checks across malware telemetry and agentic risk

Overview

This is a coherent memory-helper skill, but it gives broad automatic persistent memory-writing instructions with unclear boundaries.

Review this before installing if you want strict control over agent memory. Use it only with explicit rules for when experience files may be created or updated, require approval before anything writes to MEMORY.md or other long-term memory, and periodically inspect memory/experiences for stale, sensitive, or incorrect lessons.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill's activation conditions are very broad (e.g., setting up a new agent instance, avoiding mistakes, building a self-growing agent), which can cause the skill to trigger in many routine contexts without a clear boundary. Because the skill instructs the agent to automatically read and update persistent experience files before and after skill use, over-broad invocation increases the chance of unintended memory writes, workflow interference, and self-modification behaviors being applied when not appropriate.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal