Back to skill

Security audit

晨钟

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed personal morning-briefing skill that reads user-configured local notes and logs, with no artifact evidence of hidden upload, destructive behavior, or credential use.

Install only if you are comfortable letting the skill read the local diary, conversation, work-log, idea, and project files you configure. Keep data source paths narrow, exclude sensitive or third-party confidential material, review the listed sources in each briefing, and disable the cron or reset the data pool if the briefings become too broad.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The phrase '每次交互后自动' creates an overly broad, always-on collection model without clearly limiting which interactions are in scope or excluding sensitive conversations. In a skill that reads journals, logs, and AI conversations, this ambiguity can cause unexpected capture and analysis of personal data beyond what the user reasonably intended.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This section describes scanning recent diaries, session logs, idea files, and project notes to extract priorities, but it does not provide proportionate warnings about the sensitivity of those materials or the risks of continuous profiling. Because these sources may contain intimate personal, work, or confidential information, insufficient disclosure and control can lead to privacy harm and unintentional oversharing in generated briefings.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.