Prompt Log

Security checks across malware telemetry and agentic risk

Overview

This skill is a local transcript-export helper whose sensitive-data risk is expected for its purpose, with no evidence of exfiltration or hidden behavior.

Install only if you intend to extract local AI session history. Treat generated transcripts as sensitive, avoid committing .prompt-log or transcript files to shared repos, choose an explicit protected output path when needed, and inspect any separately obtained extract.sh before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states that it writes a markdown transcript to disk, but it does not warn users that the transcript may contain sensitive prompts, code, secrets, or session history copied from the source logs. This creates a realistic risk of unintended data exposure through insecure output locations, checked-in files, or shared workspaces, especially because the default output path is automatic and may encourage casual use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal