Back to skill

Security audit

Knowledge Collector

Security checks across malware telemetry and agentic risk

Overview

This skill has a legitimate knowledge-collection purpose, but it can automatically ingest group-chat or folder content into a shared knowledge store without enough scoping or user control.

Review before installing in any real group-chat or shared workspace. Limit activation to approved channels or explicit commands, require preview and confirmation before saving, restrict batch imports to intended folders, and add rules for sensitive data, retention, deletion, and reviewer access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill describes automatic recognition of technical content in group chats without clear scoping, consent, or trigger boundaries. In a knowledge-collection context, this can cause unintended capture of sensitive internal discussions, source snippets, incident details, or personal data shared in ordinary collaboration, increasing privacy and data-governance risk.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill explicitly auto-activates on technical keywords in group chats without requiring an explicit user command or consent. That creates a real risk of unintended collection and processing of ordinary conversation, which can capture sensitive operational details and trigger downstream storage and notifications.

Vague Triggers

Low
Confidence
89% confidence
Finding
The batch import flow accepts a user-specified folder path and scans multiple file types, but the skill text defines no path restrictions, sandboxing, or exclusion rules. This can lead to over-collection of unrelated files or sensitive local content if the path is broad, mistaken, or abused.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes automatic monitoring of group chat content, structured extraction, storage, and reviewer notification, but provides no user-facing disclosure, consent, or privacy warning. This is dangerous because users may not realize their messages are being ingested and redistributed, increasing privacy, compliance, and confidentiality risk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The collect flow persists user-provided text and extracted metadata into the domain knowledge store automatically, but this file shows no consent, warning, minimization, or sensitivity checks before storage. Because the input may contain project identifiers, equipment details, operational incidents, or other sensitive business information, silent persistence increases the risk of privacy leakage, over-collection, and retention of confidential data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.