Back to skill

Security audit

NxHUB Voice Notes to Reminders

Security checks across malware telemetry and agentic risk

Overview

This skill coherently builds a local reminder/calendar tool from NxVET voice-note transcripts, with sensitive access disclosed and no evidence of hidden sending or destructive behavior.

Install only if you are comfortable giving the tool an NxVET API key that may read organization data. Keep .env, state, and output out of git and cloud sync unless explicitly approved, and use the REST/local-file path if you want the narrowest network behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
84% confidence
Finding
The file directs the tool to retrieve full transcripts, clinical notes, raw audio, and NxHub conversation details, which may contain highly sensitive veterinary-client and clinical data. Although the broader skill claims local-only processing, this reference lacks data-minimization guidance, least-privilege scoping, or field restrictions, increasing the chance of unnecessary collection and overexposure of sensitive content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.