Security audit
超级日记 Agent Control
Security checks across malware telemetry and agentic risk
Overview
This skill coherently connects agents to a diary service with disclosed read access and user-confirmed note creation.
Install only if you trust the diary service and GitHub package source. The skill can read private diary content through your configured key and can create new notes only after explicit confirmation, so review requested searches and write confirmations carefully.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
