Back to skill

Security audit

Colleague.skill

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent and non-executable, but it creates long-lived coworker behavior profiles with weak consent, retention, and local-security controls.

Install only if your workplace permits this kind of colleague documentation. Keep entries limited to necessary work facts, avoid health, family, protected-class, speculative, or reputation-harming notes, and get consent or organizational authorization where required. Treat ~/.colleague-skill as sensitive local data, restrict access, and regularly review or delete stale profiles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly encourages creating and preserving profiles about coworkers' behavior, preferences, relationships, and institutional knowledge, including after they leave, but does not meaningfully warn about consent, employment-law, HR, or workplace privacy risks. Even if storage is local-only, this kind of sensitive profiling can create legal, ethical, and insider-risk issues if users record subjective or sensitive observations about identifiable colleagues without clear guardrails.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger for Profile Building Mode is broad enough that ordinary user discussion about a coworker could implicitly invoke persistent profiling behavior without a clearly bounded consent step. In this skill, unintended activation is more concerning because the resulting data is sensitive workplace behavioral profiling stored across sessions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The Active Mode trigger overlaps with normal workplace advice-seeking, so routine questions about collaboration could cause the system to load and update a stored profile without the user realizing persistent memory is being used. Because the skill is specifically designed to accumulate colleague-specific behavioral data, ambiguous activation increases privacy and misuse risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Departure Mode can be triggered by generic mentions of former colleagues, which risks reviving and applying preserved personal profiles in contexts where the user did not clearly request that. Given the skill's goal of retaining institutional memory after someone leaves, vague activation can extend the lifetime and use of sensitive workplace inferences beyond user expectations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Multi-Colleague Mode is triggered by broadly phrased requests about team dynamics, which could lead to comparative profiling and inference about multiple individuals from ordinary conversational prompts. This is especially sensitive because the skill aggregates interpersonal traits, friction points, and behavioral patterns that can amplify privacy and fairness harms when compared across people.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This reference guide operationalizes systematic profiling of coworkers across sensitive behavioral and interpersonal dimensions, including stress signals, decision patterns, trust factors, and unique institutional knowledge, without any privacy guardrails, consent requirements, data-minimization guidance, or warnings against misuse. In the context of a self-learning skill that persists observations over time, this can enable covert employee surveillance, manipulative targeting, unfair evaluation, and retention of sensitive quasi-HR data beyond appropriate purposes.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The template explicitly directs persistent storage of cumulative colleague interaction logs under a hidden local path, but provides no warning that the data may contain sensitive workplace observations, inferred traits, and reputation-affecting material. In this skill’s context, the omission is more dangerous because the stated purpose is to build enduring profiles of coworkers over time, increasing privacy, surveillance, and misuse risks if the data is accessed, retained indefinitely, or shared.

Missing User Warnings

High
Confidence
99% confidence
Finding
The template normalizes recording subjective behavioral inferences, stress signals, communication patterns, and second-hand claims about a colleague without any caution about consent, verification, bias, or reputational harm. This is especially dangerous in a skill designed to 'distill work styles' and preserve what people contributed after they leave, because unverified or speculative notes can become durable profiles that influence employment-related judgments and spread inaccurate or sensitive personal information.

Session Persistence

Medium
Category
Rogue Agent
Content
### Problem-Solving Style
- **Thinking**: top-down (answer-first) / bottom-up (data-first)
- **Processing**: visual thinker / verbal thinker / needs to write
- **Approach**: solo solver / talks through problems
- **Crisis Response**: calm / action-oriented / needs to process
Confidence
81% confidence
Finding
write - **Approach**: solo solver / talks through problems - **Crisis Response**: calm / action-oriented / needs to process ### Collaboration Manual - **Best Pitch**: how to present ideas (data-first

VirusTotal

49/49 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.