Back to skill

Security audit

Hizal End

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent, but needs review because it can auto-run at session wrap-up and modify or delete stored memory without explicit confirmation.

Install only if you are comfortable with an end-of-session skill that may activate on ordinary wrap-up language and can change stored agent or project memory. Use it with explicit end-session intent, review any promoted memory carefully, and avoid deleting original context unless you have separately confirmed the promotion succeeded and the source chunk is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill is configured to self-trigger on broad, ordinary wrap-up phrases such as 'I'm done' or 'that's it for now,' which can cause it to run during normal conversation without explicit user intent. Because this skill performs session-closing and memory-consolidation actions, accidental activation could prematurely end work or initiate unintended memory handling operations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to write knowledge/convention records and optionally delete original context chunks, but it provides no requirement for explicit user consent or even a warning that persistent project memory may be modified. In a memory-management skill, this is particularly risky because it can silently promote transient observations into shared knowledge or delete source context, creating integrity, privacy, and auditability problems.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.