Back to skill

Security audit

Memory Optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a local memory-file analysis and cleanup tool whose file modifications are purpose-aligned and require an explicit apply flag.

Before using --apply, run the default dry run first and consider --backup, because deduplication and cleanup can rewrite local agent memory files and may remove context you wanted to keep.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly promotes an auto-fix mode that can deduplicate, re-index, and reorganize memory files, but the description does not clearly warn that these actions may alter or delete user-authored data. In the context of agent memory stores, incorrect deduplication or stale-entry cleanup can silently remove important context, causing data loss or behavioral degradation.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The manifest explicitly advertises that the skill can 'auto-fix common issues' but provides no warning that files may be modified, backed up, or require user confirmation. For a skill that analyzes and optimizes agent memory files, silent modification of user data increases the risk of unintended data loss, corruption, or unsafe changes to operational memory used by other tools.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.