Back to skill

Security audit

Daily Digest

Security checks across malware telemetry and agentic risk

Overview

This skill locally creates a dated Markdown digest from memory notes and does not show hidden network access, credential use, or destructive behavior.

Install this only if you are comfortable with memory notes being summarized into persistent local files. Review generated digests before sharing or syncing them, and be deliberate before enabling daily automation because sensitive details could be carried forward automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
92% confidence
Finding
The README states that the skill generates and saves a daily digest derived from memory notes and broader interactions, but it does not clearly warn users that potentially sensitive conversation content will be written to persistent storage on disk. This can create an unexpected privacy and data-handling risk because users or operators may enable or schedule the skill without understanding that retained summaries of interactions will be stored in files.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.