Back to skill

Security audit

Nora Persona Framework

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended to manage AI personas, but its broad and proactive activation can steer future assistant behavior before the user clearly opts in.

Install only if you want a proactive persona-management assistant. Before allowing it to write anything, confirm the exact file path, review the full proposed persona or diff, and avoid storing sensitive personal preferences unless you are comfortable with them influencing future sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The changelog explicitly documents ultra-broad trigger matching that activates on vague, everyday phrasing, which can cause the skill to enter a persona/file-generation workflow without sufficiently specific user intent. In a skill that creates local files and modifies assistant behavior, ambiguous activation increases the risk of unwanted state changes, consent fatigue, and accidental collection or persistence of user preferences.

Vague Triggers

High
Confidence
94% confidence
Finding
The README explicitly states that even if the user says nothing, the AI will proactively suggest creating a persona in a future conversation. That broad, unsolicited activation behavior can cause the skill to trigger outside clear user intent, increasing the risk of unwanted behavior, surprise file generation flows, or persistent manipulation of conversation direction.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.