Kiro Intercom

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple shared chat-file helper for Kiro instances, with the main risk being that anything written there persists and can be read by other instances with file access.

Install only if you intentionally want multiple Kiro instances to share messages through `memory/kiro-chat.md`. Do not put passwords, tokens, private personal data, or high-impact instructions in that file, and verify important requests before acting on messages from another instance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs agents to write conversation content into a shared file used by multiple Kiro instances, but it does not warn users that prompts, responses, or sensitive context may be persisted and exposed across environments. This creates a real confidentiality and data-leakage risk, especially if one instance handles secrets, private user data, or instructions that another instance should not automatically inherit.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal