quantum-daily-tracker

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed quantum-paper tracker that fetches public RSS feeds and writes local Markdown notes for daily digests.

Install this if you want an agent to fetch public quantum-paper RSS feeds and maintain a local Markdown tracker. Before enabling daily or catch-up runs, confirm where the quantum-tracker files and memory/last-run.txt will be written, and reset that state file if the tracker starts from the wrong date range.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad enough that ordinary user requests like 'update papers' or 'fill in missing papers' could invoke the skill unexpectedly. Because this skill performs automated fetching and file writes, ambiguous invocation boundaries can cause unintended network activity and local state changes without clear user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow explicitly directs the agent to create notes, generate summaries, update a dashboard, and modify a state file, but it does not disclose these side effects to the user at the point of use. Hidden write behavior is risky because a user may believe they are requesting analysis only, while the skill persists content and changes local tracking state automatically.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal