Back to skill

Security audit

Graph Memory

Security checks across malware telemetry and agentic risk

Overview

The skill reads local graph memory from prior sessions and can broadly surface people, files, projects, and errors without clear privacy or authorization limits.

Review this before installing in shared or sensitive environments. Use it only if you want agents to answer from accumulated prior-session memory, and treat outputs about people, files, projects, and errors as potentially sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance encourages broad natural-language use such as asking what the system 'knows' about entities and how items are connected, without limiting scope to the current user, current workspace, or non-sensitive data. That makes it easier for an agent to retrieve accumulated historical memory that may include unrelated or sensitive prior-session information in response to vague prompts.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill queries persistent session-derived memory but does not warn that results may contain sensitive information from prior interactions, including people, files, projects, and errors. Without a privacy warning, users and agents may treat the memory as harmless context and inadvertently surface stored data beyond the current conversation's intended scope.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly promotes broad retrieval across accumulated session memory categories such as people, projects, tools, files, and errors, yet provides no guardrails against exposing sensitive prior-user data. In a persistent memory context, this can enable cross-session data leakage, profiling, or disclosure of confidential workspace details through ordinary natural-language requests.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.