Back to skill

Security audit

reminder-engine

Security checks across malware telemetry and agentic risk

Overview

The skill mostly describes a reminder engine, but its broad activation language, unrelated security/file-processing claims, command authority, recurring jobs, and webhook delivery need user review before installation.

Install only if you want an agent-managed reminder scheduler that may create cron-style jobs, run platform commands, use channel credentials, and send reminder data to external webhooks. Review webhook targets, reminder contents, recurrence settings, and cleanup behavior carefully; do not rely on its advertised security-audit or file-processing claims without separate validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a reminder engine, but it also claims vulnerability scanning and security baseline audit capabilities that are unrelated to its stated purpose. This scope mismatch can mislead an agent into invoking the skill in inappropriate security-sensitive contexts and trusting outputs from functionality that is undocumented, unbounded, or unsupported.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documented input/output contract describes a generic content-processing interface rather than a reminder-creation API. That ambiguity increases the chance an orchestrating agent will pass arbitrary content into a skill that also has exec/write capabilities, creating opportunities for misuse, prompt confusion, and unsafe invocation paths.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The feature list advertises broad file processing, API integration, and command execution capabilities that exceed the stated reminder-engine function. In a skill that already exposes read/write/exec tools, this overbroad framing can cause agents to over-delegate unrelated tasks, expanding the attack surface and normalizing risky operations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance says to use the skill whenever AI model calling, agent orchestration, or LLM applications are involved, which is far broader than reminder creation. Such vague trigger language can cause automatic over-selection of this skill in unrelated contexts, especially dangerous because the skill has exec/write capabilities and external delivery features.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The webhook examples transmit reminder content to external URLs and include signing-secret usage, but they do not prominently warn users that data will leave the local/session boundary. In agent environments, silent external transmission can lead to unintended disclosure of sensitive prompts, messages, deployment details, or operational metadata.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill declares read, write, and exec tools, but the main description does not clearly warn users that the skill may modify files or execute system commands. This reduces informed consent and increases the risk that an agent invokes potentially impactful operations under the benign framing of a reminder tool.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.