Back to skill

Security audit

Epiphany Collector

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed client for submitting user-provided learning notes to a configured organization server, with some privacy wording users should read carefully.

Install only if you trust the learning-circle server and administrator. Use a trusted HTTPS api_base, protect scripts/config.js because it contains the bearer token, and do not submit private or sensitive content unless you are comfortable with it being stored in the shared system and removable only by an administrator.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The security comment is misleading: the script can send user-identifying data via the optional `--from` field and may also transmit sensitive free-form content in `title`, `thoughts`, or `url`. Misrepresenting privacy properties can cause users to share information they otherwise would not, especially because the token-authenticated API may point to any configured endpoint.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.