Connect

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable description of a memory-based people-matching skill; it handles a sensitive concept, but the behavior is disclosed and no hidden runtime authority was found.

Before installing, confirm you are comfortable with a skill concept that matches people using personal memories and emotional patterns. Use it only where memory matching is opt-in, sharing requires explicit approval, and users have clear controls to exclude, revoke, or delete matchable memories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly describes cross-user memory bridging, emotional resonance matching, and surfacing latent connections from long-term memory graphs, which implies processing highly sensitive personal and potentially intimate data across users. Although it claims a privacy-first architecture and explicit consent, the file does not clearly define consent boundaries, data minimization, sharing rules, or user-facing warnings about how cross-user inference and memory-derived matching operate, creating a meaningful privacy and misuse risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal