Back to skill

Security audit

Agent Notebook

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local memory skill, but it deserves review because it encourages broad long-term logging and can enable recurring jobs that read, rewrite, and prune memory files.

Install only in a trusted workspace where plaintext memory files are acceptable. Before enabling cron or scheduled tasks, inspect the exact jobs and decide whether recurring background processing is intended. Do not store passwords, tokens, private keys, regulated personal data, sensitive customer data, or secret locations in MEMORY.md or daily notes. Review and prune retained memory regularly, and remove or narrow the email, calendar, social, and catch-all monitoring guidance unless you explicitly want those integrations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The heartbeat routine expands this skill from memory persistence into active monitoring of email, calendar, and social notifications, which is outside the declared memory-management scope. This creates an unjustified standing instruction for external service access and increases the chance an agent will perform sensitive account checks without clear user consent or least-privilege boundaries.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Documenting periodic monitoring of external communications/services in a memory-system skill normalizes access to sensitive sources that may contain private or regulated data. Because the capability is not justified by the skill's purpose, it encourages overbroad behavior and could lead to unauthorized collection, review, or retention of user data.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The template explicitly invites storing "infrastructure details" and "API keys location" in long-term memory, which normalizes retaining operationally sensitive information beyond what is necessary for general personalization. In a persistent-memory skill, this increases the chance that secrets, secret-adjacent metadata, or internal system details are later exposed to the model, logs, other contexts, or unauthorized users.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README promotes persistent storage of session data and long-term extraction into MEMORY.md, but it does not pair that behavior with explicit privacy, retention, consent, or minimization guidance at the point of setup. In a memory skill, this omission is materially risky because users may store sensitive operator, customer, or credential-adjacent data indefinitely and later surface it across sessions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The cron setup section describes automated jobs but does not clearly warn that they will continue to read from and write to workspace memory files without interactive review. That creates risk of silent data accumulation, unintended processing of sensitive content, and persistence beyond what the operator expects.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The top-level description uses broad activation language around 'persistent memory' and related phrases, which can cause the skill to trigger in situations where the user is only asking general questions rather than requesting installation or use of this memory system. Over-broad invocation increases the chance that persistent-storage behavior is introduced without clear user intent, amplifying privacy and data-retention risks elsewhere in the skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger section lists many broad conditions but does not define boundaries for when the skill should not run. In a skill that persists user context and configures automation, ambiguous triggering is dangerous because it can lead to unrequested storage of sensitive information or environment changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The installation guidance tells the agent to seed long-term memory with operator identity, relationships, boundaries, and preferences before providing a clear upfront warning about persistence, retention, and sensitivity. This creates a meaningful privacy risk because users may not realize that personal details will be stored across sessions in plaintext files.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The instructions tell the agent to write notable inbox entries to daily notes, update MEMORY.md, and clear processed entries, which are state-changing and deletion-like actions. Without an explicit warning, confirmation policy, or disclosure to the user, the skill encourages silent modification of persistent records and removal of source material that may be needed for auditability or recovery.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The script automatically appends extracted content from daily notes into MEMORY.md and modifies the source notes by adding an extraction marker, but it provides no consent gate, preview, or retention warning. Because daily notes may contain sensitive or unintended long-term information, this can cause silent persistence of private data and surprise file modifications, especially when run unattended as a nightly job.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The service-check section authorizes broad monitoring categories plus 'Any other periodic monitoring' without defining boundaries, permissions, or approved integrations. In an agent skill, this can expand behavior beyond user intent, leading to unauthorized access to external services, privacy overreach, or excessive background data collection.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The routine instructs the agent to write to daily notes, update MEMORY.md, and clear processed inbox entries, but it does not require explicit user confirmation or even a warning that data will be modified or deleted. For a persistence system, silent mutation of memory files can cause data loss, corruption of long-term context, and non-transparent changes that are hard for the user to audit.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The template encourages accumulation of personal and sensitive context such as important people, hobbies, work details, and API-key-related information without clear data minimization, consent, retention, or sharing safeguards. Because this file is meant to persist across sessions, it can become a high-value privacy target and increase the blast radius of any prompt leakage, workspace compromise, or accidental inclusion in shared contexts.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The template explicitly asks for 'internal monologue' and 'honest reflection' that is 'unfiltered,' which can encourage generation or storage of chain-of-thought-like reasoning rather than user-facing summaries. In a persistent memory skill, this is more sensitive because such content could be retained across sessions and may capture hidden reasoning, emotional state, or unnecessary private data without clear boundary-setting.

Ssd 3

Medium
Confidence
87% confidence
Finding
The README frames the goal as preserving broad session and operator context across runs, which encourages durable retention of natural-language data that may include sensitive or unnecessary details. In this skill context, that is more dangerous because the whole feature is cross-session persistence, so any over-collection becomes systemic rather than incidental.

Ssd 3

High
Confidence
96% confidence
Finding
Telling the agent to 'write everything' to daily notes and then distill significant items into durable memory is an explicit over-collection pattern. This is dangerous because it predictably captures confidential prompts, personal data, internal project details, or security-sensitive information, then promotes selected content into longer-lived storage where it can leak into future sessions and outputs.

Ssd 3

Medium
Confidence
84% confidence
Finding
Claiming that every session starts with 'full context' implies broad reuse of previously stored information, including data that may no longer be appropriate, necessary, or safe to surface. In a memory system, this increases the chance of privacy leakage, stale-context misuse, and accidental inclusion of prior sensitive material in new tasks.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly encourages storing broad operator-specific and personal context in persistent memory, including relationships and boundaries, which can easily capture sensitive personal data. Because this data is intended for reuse across sessions, compromise of the workspace or accidental sharing can expose a durable profile of the operator.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instruction to write 'everything significant' and to be 'raw and verbose' strongly biases the agent toward over-collection of sensitive user content, including secrets, personal details, and confidential project information. Since these notes are persisted and later mined, a single overbroad logging decision can create long-lived data exposure.

Ssd 3

Medium
Confidence
95% confidence
Finding
The nightly extraction routine automates harvesting entries from raw daily notes into long-term memory, which compounds privacy risk by promoting transient information into durable storage without human review. Automated semantic extraction can misclassify sensitive material as 'significant' and make it harder to discover and delete later.

Ssd 3

Medium
Confidence
88% confidence
Finding
The script is explicitly designed to persist information from daily notes into a long-term MEMORY.md file, which creates a real privacy and data-minimization risk. In this skill context, persistent memory is the intended feature, but the retention is broad and not bounded by sensitivity rules, consent checks, or redaction, so sensitive user content may be stored longer than necessary.

Ssd 3

Medium
Confidence
96% confidence
Finding
When a note matches generic significance keywords, the script copies the entire body into persistent memory, which can easily include unrelated sensitive material, secrets, or private user data. Because the trigger terms are broad and the body is appended verbatim, this increases the chance of over-collection and long-term exposure of confidential information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.