Todo Management 1.1.2

Security checks across malware telemetry and agentic risk

Overview

This skill is a local SQLite todo manager with normal todo deletion abilities and one inert packaging oddity.

Use this for local todo management, but avoid storing secrets in todos because they persist in todo.db. Be careful with clear, remove, and --delete-entries actions. Do not run npm or pnpm install in the skill folder unless the publisher explains why those unused package files are present.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

46/46 vendors flagged this skill as clean.

View on VirusTotal