Back to skill

Security audit

神经缓存增强

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local associative-memory helper, but users should understand it can retain and move project context across sessions and projects.

Install only if you want a local memory layer that persists project and user context across sessions. Avoid storing secrets, credentials, regulated data, or confidential client information, and review any cross-project transplant before using it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger keyword list includes the generic English word 'associative', which is broad enough to match ordinary conversation and unintentionally activate the skill. In a skill that can persist memory and has `exec` capability declared, accidental activation can lead to unintended storage, retrieval, or follow-on tool usage in contexts where the user did not intend memory operations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages storing facts, preferences, decisions, and context into persistent local memory but does not prominently warn that user and project information may be retained across sessions. This creates a privacy and data-governance risk because operators may persist sensitive content without informed consent or retention controls.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The cross-project 'transplant' feature enables memory migration between projects without clearly warning about confidentiality boundaries, data ownership, or accidental leakage of sensitive context. In this skill's context, cross-project transfer materially increases the chance of unauthorized sharing of decisions, internal lessons, architecture details, or user-specific information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.