activity-analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill transparently reads local ActivityWatch history for productivity analysis, but users should understand it may share sensitive window titles with the AI model.

Install only if you are comfortable letting the AI model see recent ActivityWatch app names and window titles. For better privacy, edit the script to remove the raw result print and aggregate by app or category before running.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This script collects and prints detailed ActivityWatch window/application history, including app names and window titles, which can expose sensitive user information such as document names, websites, chats, or internal systems. Because it emits this data directly to stdout without an explicit privacy notice, consent check, minimization, or redaction, an agent or downstream consumer could access private activity data unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal