Back to skill

Security audit

archive-tool-free

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local content-archiving skill, with some privacy and trigger-scope cautions but no evidence of hidden, destructive, or deceptive behavior.

Install only if you want the agent to create a persistent local Markdown archive of full content, summaries, tags, search indexes, and recall history. Avoid archiving confidential, personal, or copyrighted material unless you are comfortable storing it in the workspace, and review the archive directory periodically for cleanup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation scope is excessively broad and includes unrelated keywords such as SEO and ranking optimization, which increases the chance the skill will be invoked in contexts outside its intended archive function. In an agent environment with read/exec capabilities, unintended invocation can lead to unnecessary file writes, processing of unrelated user data, or execution of commands under the wrong workflow.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs agents to save complete external content locally and retain it, but does not warn users about local file creation, persistence, copyright concerns, or the possibility of storing sensitive or personal data. In practice, this can cause accidental retention of confidential material and silent writes to the local workspace, especially because the skill has read and exec tools available.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The described proactive recall behavior may surface previously archived material in later sessions without clear user expectation or notice. That can expose sensitive notes, research topics, or prior archived content in unrelated workflows, creating a privacy and contextual data-leak risk even if the feature is only described conceptually here.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.