Back to skill

Security audit

Soul Decision Engine

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent as a decision-memory tool, but it encourages automatic recording and cloud/team sharing of potentially sensitive decisions without enough consent, provider, retention, or access-control detail.

Review this skill before installing in business, HR, client, legal, or strategy contexts. Use it only with a known cloud provider and explicit team consent, keep sync disabled until configured, avoid storing long-lived API keys in local files, and define retention and sharing boundaries before recording or syncing decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill gives conflicting secret-handling guidance: it says API keys should be supplied via environment variables and not hardcoded, but then recommends storing them in a local credentials directory. Even if gitignored, storing long-lived secrets on disk increases exposure to local compromise, accidental inclusion in backups, permissive file permissions, or other tools reading that directory.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill promotes cross-device cloud sync of decision memory, snapshots, and team sharing, but does not give a prominent warning that potentially sensitive decision data will be transmitted to external services. In this skill's context, the synced content may include strategic, HR, customer, or project-isolated information, so silent or underexplained transmission materially raises confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The integration guidance describes automatic meeting/decision recording and team-wide cloud sharing without explicit notice, consent, or disclosure controls. In a decision-support skill that may process internal strategy, personnel assessments, and client data, automated recording and broad sharing can expose confidential or regulated information to unintended recipients.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.