Back to skill

Security audit

Backup Manager

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward backup-management skill with visible, purpose-aligned commands, though users should confirm destinations before cloud syncs or deletion-style backup operations.

Before using it, replace every placeholder path and destination, run dry-runs where available, confirm cloud provider/account/path and whether encryption is needed, and carefully review commands using --delete or rm -rf because they can remove backup data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill includes rclone sync examples that can send user documents to third-party cloud providers without an explicit warning to verify the remote destination, account, encryption settings, or data sensitivity. Because backups often contain sensitive personal and system data, this can lead to unintended off-device disclosure if the agent executes the examples without informed confirmation.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal