Back to skill

Security audit

Meta Agent Optimizer Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent learning-log helper, but it can automatically persist conversation context, raw errors, parameters, and project rules into repository files without strong consent or redaction controls.

Review this skill before installing in sensitive projects. Use it only with a clear policy to confirm each write, redact tokens and private data from errors and parameters, keep .learnings local or gitignored by default, and manually review any promotion into CLAUDE.md or AGENTS.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The auto-trigger phrases are broad enough to activate on normal conversation, causing the agent to create or update persistent logs without a clear, deliberate user request. In this skill's context, that increases the chance of unintended data capture and repository modification, especially because the skill is designed to persist user corrections and errors.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs creating persistent files in the workspace but does not prominently warn that it will write repository data. Users may believe they are invoking lightweight assistance, while the skill actually alters project state and creates long-lived records that could later be committed or shared.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill directs the agent to record user-provided corrections, inputs, and context into persistent logs. That creates a clear data retention risk because natural-language context often contains secrets, internal URLs, credentials, personal data, or proprietary information that users did not intend to store long term.

Ssd 3

Medium
Confidence
95% confidence
Finding
The learning-entry template explicitly encourages saving complete context from user feedback into reusable records. In this context, that makes accidental retention of sensitive conversation content more likely and increases blast radius if the repository is shared, synced, or committed.

Ssd 3

High
Confidence
98% confidence
Finding
Logging raw error output together with used inputs or parameters is a classic sensitive-data exposure path. Error messages and command parameters frequently contain tokens, connection strings, API keys, file paths, customer data, or request payloads, and this skill persists them into searchable markdown files.

Ssd 3

Medium
Confidence
90% confidence
Finding
The automatic trigger to record any user-supplied information the agent 'did not know' turns normal conversation into persistent knowledge capture. In practice, that can sweep up confidential business facts, internal processes, or one-off sensitive clarifications and store them without informed consent.

Ssd 3

Medium
Confidence
93% confidence
Finding
Recommending team-wide repository tracking of learning logs raises exposure risk because these logs may include user-derived content, error traces, and operational details. The skill's own templates encourage retaining rich context, so repository sharing materially increases the chance of broad internal disclosure or accidental external publication.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.