Back to skill

Security audit

process-keeper

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple workflow-documentation helper that saves process notes in the project, with no executable code or hidden behavior found.

Install only if you want an agent to create reusable development process logs in your repository. Before saving or committing those logs, review them for credentials, internal URLs, personal data, security incident details, and confidential business context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description uses broad invocation phrases such as 记录流程、任务复盘、过程记录、日志记录、决策记录 without defining boundaries, exclusions, or conditions for safe use. This can cause the skill to be invoked in many unrelated contexts and may lead an agent to capture and persist sensitive project details, decision history, or operational data more often than intended.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill instructs saving process logs into docs/process/ within the repository without any warning, consent check, or guidance on filtering sensitive content. Because the workflow explicitly captures task goals, status, key files, decisions, and problem records, this creates a realistic risk of committing internal or sensitive information into source control where it may be retained or shared broadly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.