Back to skill

Security audit

magic-mirror

Security checks across malware telemetry and agentic risk

Overview

This self-reflection skill is not malicious, but it asks the assistant to keep detailed ongoing records of personal life history without a clear consent or deletion flow.

Install only if you are comfortable with the skill keeping ongoing personal reflection notes across sessions. Avoid sharing passwords, credentials, health crises, financial identifiers, or private third-party details, and check where timeline, summary, and counterfactual files are stored so you can review or delete them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill presents itself as 'just a mirror' for reflection, but it instructs cross-session recall using timeline data and sender identifiers. In a deeply personal introspection context, hidden persistence of sensitive life history can violate user expectations and create privacy risk if the data is exposed, reused, or retained without meaningful consent.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The instructions require maintaining timeline and counterfactual records across sessions, which means the skill is effectively building structured dossiers about a user's personal history and alternate-life reflections. For a self-reflection tool, this data is especially sensitive because it can reveal identity, regrets, relationships, and vulnerabilities beyond what users may expect from casual conversation.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Using sender ID for cross-session identification enables long-term linkage of intimate conversations to a single individual. In a reflective skill, that linkage increases the risk of profiling and unauthorized reconstruction of a user's personal narrative if the identifier or backing store is compromised or reused.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The skill directs retention of original emotional wording plus references to people and places, which amounts to collecting highly sensitive personal data. Because the skill is designed for vulnerable introspective conversations, these details can expose relationship networks, emotional states, and potentially identifying context if leaked or misused.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file instructs the AI to automatically append a structured session summary at the end of conversations, creating a durable-style record of user disclosures beyond what is necessary to answer the user in the moment. In an introspection skill, users are likely to share highly sensitive information, so automatic summarization increases unnecessary collection, retention, and exposure risk, especially if outputs are logged, copied, or shown in contexts the user did not explicitly request.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documented format explicitly extracts and organizes sensitive personal data including family dynamics, romantic relationships, finances, inferred psychological patterns, and named individuals. Because this skill is designed for deep self-reflection, the surrounding context makes the data especially intimate; structuring it into a reusable summary meaningfully increases privacy harm, profiling risk, and the chance of unintended disclosure to third parties.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes persistent tracking of conversation history and writing structured summaries, timelines, and counterfactual records without a clear upfront warning about retention and privacy consequences. In a self-reflection setting, users are likely to disclose unusually sensitive information, so undisclosed retention materially increases privacy harm and the chance of overcollection.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.