Back to skill

Security audit

Research Tracker

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local research-agent tracking skill, but users should trust the external CLI source and understand that research activity is stored on disk.

Install only if you trust the 1645labs Homebrew tap or Go repository, and prefer reviewing or pinning a release for sensitive work. Use it for explicit long-running research tracking, monitor stop signals and heartbeats, and avoid logging secrets or sensitive research content unless you are comfortable retaining it in the local SQLite database.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description contains broad trigger phrases such as 'research projects,' 'sub-agent coordination,' and 'autonomous investigation,' which can cause the skill to be invoked in many loosely related contexts. Overbroad invocation increases the chance an agent will use this skill when inappropriate, potentially spawning or coordinating long-running sub-agents and persisting state without sufficient user intent or review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.