Deepvista Recipe Analyze Notes

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed DeepVista recipe for reading and synthesizing notes, with sensitive-note access that users should control but no hidden or destructive behavior found.

Install only if you trust the DeepVista CLI and service with the notes you ask it to analyze. Be explicit about the note scope, review fetched content before broad synthesis when possible, and only approve saving an analysis note when you actually want a new note created.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger criteria are broad enough to match many ordinary requests about notes, such as summarizing or reviewing thoughts, without strong disambiguation. In an agent system, this can cause the skill to activate unexpectedly, leading to unnecessary access to multiple notes and broader data exposure than the user likely intended.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal