Back to skill

Security audit

08 Growth Record

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable child growth journal skill, but users should treat the child health and development details it handles as sensitive private information.

Install only if you are comfortable using the agent as a private child growth journal. Avoid entering unnecessary identifiers, review every generated report before sharing, and redact medical details, exact dates, and developmental concerns before sending anything to family groups or social media.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages generating and sharing a child's growth, developmental milestone, and medical-related reports, which involves highly sensitive pediatric and health data. Without privacy warnings, consent guidance, audience restrictions, or data-minimization controls, users may overshare a minor's personal and medical information to family groups or social platforms, creating lasting privacy and safety risks.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.