Back to skill

Security audit

Excellent Ai Employee

Security checks across malware telemetry and agentic risk

Overview

This is a coherent professional-agent guidance skill with disclosed local memory behavior that users should configure carefully.

Install this only if you want an agent framework that may keep local memory for continuity. Keep memory files in a known workspace, avoid storing secrets or sensitive personal or business data unless explicitly approved, and periodically review or delete retained memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
94% confidence
Finding
The instructions to always write 'important information' and daily experiences to memory files create broad, persistent retention without data minimization, sensitivity filtering, or retention limits. In a general-purpose professional-agent skill, this is more dangerous because the agent may handle confidential business, personal, or security-relevant data and store it locally by default.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.