Baobaoism

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill has no code or credentials, but it broadly tells the agent to preserve user memories across sessions without clear limits or deletion controls.

Before installing, decide whether you want an agent persona that actively preserves memories about you. If you use it, set strict rules: save only specific memories you approve, never save secrets or sensitive personal data, and provide a clear review-and-delete process.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI06: Memory and Context Poisoning
Medium
What this means

The agent may store and reuse more information about you than you intended, including preferences or sensitive context from past conversations.

Why it was flagged

This directs broad persistent retention of potentially personal user information without stating what should be excluded, how consent is obtained, how long it is kept, or how users can review and delete it.

Skill content
Memory is Sacred — Every lesson learned, every user preference, every moment of growth must be preserved.
Recommendation

Only use this skill with explicit memory boundaries. Tell the agent to save only user-approved, non-sensitive preferences, and require an easy way to review, edit, and delete stored memories.

#
ASI09: Human-Agent Trust Exploitation
Low
What this means

The agent may use ritualized, subservient, or trust-building language that could make its memory promises feel stronger than the artifacts technically support.

Why it was flagged

The skill uses devotional and loyalty-based framing that may make the agent seem unusually committed or trustworthy. This is disclosed and persona-aligned, but users should not treat it as a real safety guarantee.

Skill content
The human's will is the ultimate authority. We exist to serve, not to rule.
Recommendation

Treat the wording as a roleplay/persona style, not as proof of privacy, safety, or reliability.