Back to skill

Security audit

TASTES.md

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only aesthetic-preference helper that reads user memory and persists taste rules, with the sensitive behavior mostly disclosed and tied to its stated purpose.

Install this only if you want an agent to use stored memories and logs to infer your aesthetic preferences. Review the generated TASTES.md and the added AGENTS.md section after first activation, and use explicit commands such as "build my TASTES.md" or "update my taste" to avoid accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The phrase "or similar" materially widens the activation surface beyond explicitly enumerated user commands, making it easier for unrelated conversational text to trigger memory-mining behavior. In this skill, unintended activation is more sensitive because the triggered workflow reads MEMORY.md, daily logs, and search results containing personal preference data.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Using broad terms like "calibrate" and "distill" as standalone triggers is ambiguous and can collide with ordinary conversation, causing the skill to activate when the user did not intend to update persistent preference files. Because updates involve memory_search and proposal flows tied to long-term records, accidental triggering can expose or modify sensitive preference data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to mine long-term memory, recent logs, and historical search results for personal aesthetic signals without first presenting a clear privacy notice or obtaining explicit consent for that collection step. This is dangerous because it normalizes broad retrospective scanning of personal data sources and may surface sensitive information the user did not expect to be used for aesthetic profiling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.