Daily Report Skill

Security checks across malware telemetry and agentic risk

Overview

This daily reporting skill is coherent, but it can automatically read private workspace notes or conversation context and send summaries to external chat services without clear review controls.

Review before installing if your workspace memory or conversations may contain sensitive information. If used, configure only trusted channel targets, keep conversation logs and task status opt-in, and require a preview/redaction step before scheduled or multi-channel sends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly collects journal content, conversation logs, and task status, then sends the generated report through external message APIs, but it provides no warning, consent step, data minimization guidance, or channel trust boundaries. This creates a real data-exfiltration/privacy risk because potentially sensitive internal context can be transmitted off-platform automatically or with only a simple trigger.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal