Back to skill

Security audit

Notes Sync Cli Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed local Markdown note manager, but its broad unrelated routing language and under-guarded permanent deletion path need human review before installation.

Review this before installing. Use it only with a trusted notes-sync CLI, limit use to a specific Markdown vault, and avoid --force deletion unless you have a backup and have explicitly confirmed the target path. The unrelated data-analysis trigger wording should be tightened so the skill is not selected for tasks outside note management.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The skill includes overly broad and unrelated trigger phrases, such as data analysis and visualization scenarios, which can cause the agent to select this skill outside its intended note-management context. In an exec-enabled skill, accidental invocation increases the chance of unintended local file operations against user data, especially because the skill advertises create, move, and delete capabilities.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation exposes a force-delete path for physical deletion without a strong warning, confirmation requirement, or guardrails. In the context of an exec-capable file-management skill, this raises the risk of irreversible data loss from misunderstandings, prompt ambiguity, or accidental tool invocation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.