Back to skill

Security audit

YouMind

Security checks across malware telemetry and agentic risk

Overview

The skill is a straightforward YouMind CLI integration with a credential-handling caution but no evidence of hidden or malicious behavior.

Install only if you trust the YouMind CLI and want an agent to manage YouMind content for you. Prefer setting YOUMIND_API_KEY through a secure environment or secret manager, avoid putting real API keys directly on command lines, and review API calls before allowing changes to account content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly recommends passing the API key on the command line with `--api-key sk-ym-xxx` but does not warn that command-line arguments may be exposed via shell history, terminal logs, audit systems, or process listings on multi-user systems. Because this skill is specifically for authenticated API use, users are likely to copy the example verbatim, increasing the chance of credential disclosure and subsequent unauthorized access to the YouMind account and data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.