Back to skill

Security audit

金字塔记忆架构

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent memory-architecture guide, but it includes broad workspace scanning, file rewriting/deletion guidance, cron setup, and GitHub push steps with inconsistent confirmation boundaries.

Install only if you want this skill to manage agent memory files across a workspace. Before using cleanup, cron, or sync workflows, require an explicit diff or dry run and a separate confirmation before any deletion, commit, tag, push, or scheduled task creation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a memory architecture and workspace initialization guide, but it also instructs the agent to perform repository-side actions such as version bumps, git commits, tagging, and GitHub pushes. Expanding from local documentation structure into source-control publication increases the skill’s authority and can lead to unintended external changes if invoked under its broad trigger conditions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Directing the agent to push changes to GitHub repositories is a materially sensitive capability that is not justified by the stated purpose of this skill. In practice, this can publish unreviewed changes, modify the wrong repository, or create durable external side effects from what appears to be an internal organization skill.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The document first says redundancy checks should only recommend cleanup after owner confirmation, but later instructs deletion of lower-level duplicate content before that confirmation. This contradiction can cause the agent to delete or rewrite workspace files without authorization, increasing risk of data loss and policy corruption.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger scope is extremely broad, covering common situations like creating agents, initializing workspaces, memory design, redundancy checks, and rule entry guidance. Overbroad activation increases the chance the skill will run in loosely related contexts and apply file-modifying or repo-affecting instructions when the user did not specifically request them.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill authorizes scanning, writing, and deleting markdown content across the workspace, but does not provide an upfront warning that these operations may modify or remove files. In combination with the broad trigger scope and later cleanup logic, this can lead to silent or surprising workspace changes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.