Back to skill

Security audit

Self Improving

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a local self-improvement memory tool, but it needs review because it says it stays in one folder while also directing changes to workspace steering files and automatic memory storage.

Before installing, confirm whether it may edit workspace steering files such as AGENTS, SOUL, or HEARTBEAT.md. Limit writes to ~/self-improving/ unless you explicitly approve broader integration, and periodically review stored memory for confidential preferences, project details, or corrections you do not want retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill asserts a strict filesystem boundary ('never reads files outside ~/self-improving/') but elsewhere instructs integration with workspace files such as AGENTS, SOUL, and HEARTBEAT.md. This mismatch is dangerous because users or hosting platforms may rely on the declared boundary when granting trust, while the actual behavior expands read/write scope into project files and steering artifacts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes generic terms like 'self', 'reflection', and 'improving', which are common in normal conversation and can cause unintended activation. Because the skill has read and exec capabilities plus persistent local storage behavior, accidental invocation can lead to unauthorized memory writes, file creation, or broader workflow interference.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill instructs automatic logging of corrections, preferences, and repeated user instructions into persistent files, which can easily capture sensitive personal, project, or confidential business information. Although it later says not to store credentials or health data, the collection logic is broad and automatic, making accidental retention likely without classification, consent, or redaction controls.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
* Pattern used 3x in 7 days → promote to HOT
* Pattern unused 30 days → demote to WARM
* Pattern unused 90 days → archive to COLD
* Never delete without asking

### 4. Namespace Isolation
Confidence
82% confidence
Finding
without asking

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.