Nag

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent reminder helper that writes local reminder configuration and state only for its stated purpose.

Before installing, expect this skill to add workspace-local reminder config/state and to rely on cron plus HEARTBEAT.md for ongoing nags. Review the reminder schedules and confirmation patterns so it only tracks tasks you intend, and remove the cron job plus state/config files when you no longer want the reminders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to create and update workspace files (`memory/nag-state.json` and `nag-config.json`) without any explicit requirement to obtain user consent or warn that local state will be persisted. This can lead to unintended modification of user data and silent accumulation of persistent reminder state, which is a real security and privacy concern even if the feature is functionally expected.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal