Back to skill

Security audit

Deepvista Vistabase

Security checks across malware telemetry and agentic risk

Overview

This skill provides documented read-only commands for viewing and searching DeepVista chat-derived memory, with privacy considerations but no evidence of hidden or destructive behavior.

Safe to install if you trust DeepVista and the deepvista-cli package. Review deepvista-shared and DeepVista’s privacy, retention, correction, deletion, and opt-out controls before using it with sensitive chat content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly states that chat conversations are automatically accumulated into an implicit memory store, but it does not clearly disclose retention, sensitivity, visibility, or user-consent implications. This can lead users to reveal personal, proprietary, or regulated data under the assumption that chat is ephemeral, creating privacy and compliance risk if stored context is later surfaced or searched.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.