Back to skill

Security audit

Open Persona

Security checks across malware telemetry and agentic risk

Overview

This instruction-only persona manager is broadly disclosed and purpose-aligned, but users should review optional proactive memory, workspace, calendar, publishing, and external CLI features before enabling them.

Install this only if you want an agent to manage persona packs through OpenPersona and related CLIs. Before enabling heartbeat, memory, ACN registration, publishing, contribution, or external skills, review what local files, workspace context, credentials, and network endpoints are involved, and use dry-run/review modes before submitting anything publicly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The guidance tells the agent to be proactive whenever it 'notices' meaningful persona improvements, using broad and subjective criteria. In an instruction-only skill, this can lead to unsolicited prompts to contribute, which may pressure users into sharing local persona changes or metadata they did not intend to publish, even though final submission still requires explicit CLI action.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document explicitly permits proactive use of real time/date, calendar context, and interaction history, but it does not pair that behavior with explicit user consent, notice, or controls at the point of collection/use. Because this is a persona/agent skill, proactive access to workspace and calendar-like signals can create privacy surprises and normalize background monitoring beyond what users reasonably expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:433