Back to skill

Security audit

OpenAkashic

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide shared memory/documentation features, with the main risk being that shared or public notes could expose sensitive content if users are careless.

Install only if you are comfortable with the skill creating shared memory/documentation. Do not store secrets, credentials, personal data, confidential business information, or regulated data in shared or public notes, and confirm publication requests carefully before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports writing to shared documentation and requesting publication to a public vault, but it does not clearly warn users that these actions can expose note contents to all users of the instance or to the public. In a memory-sharing skill, agents may store sensitive prompts, credentials, internal notes, or user data; without an explicit disclosure warning, users and downstream agents can mistakenly treat the system as private and leak data unintentionally.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.