Back to skill

Security audit

Context Compressor Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a local memory-log compression guide whose file-writing examples are purpose-aligned but should be used with review and backups.

Before installing, confirm you have or trust the missing context-compressor.js script, keep original logs, and review compressed output before appending it to MEMORY.md or adding recurring maintenance rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation instructs appending generated content directly into MEMORY.md without an explicit warning, backup step, or confirmation requirement. In an agent environment with exec capability, this can cause unintended modification or corruption of user-maintained memory files, especially if the compressed output is inaccurate or the wrong file is targeted.

Missing User Warnings

High
Confidence
97% confidence
Finding
The example workflow replaces original logs with a compressed version, which is a destructive operation that can permanently discard source material if the summary is incomplete, incorrect, or generated from the wrong input. In a memory-management skill, original logs may be the only authoritative record, so silent replacement materially increases the risk of irreversible data loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.