BookNotes Reading Notes and Book Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill is a local book-note tracker that writes reading notes on your machine and shows no evidence of hidden network, credential, purchase, or destructive behavior.

Install if you are comfortable with your agent creating and updating local files under a books directory. Use a dedicated notes folder, keep backups of important notes, and avoid storing sensitive personal reading notes unless you are comfortable with them being reused later for summaries or cross-references.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill describes activation in very broad natural-language terms such as 'Read a book. Tell your agent what you learned,' without defining clear invocation boundaries, command formats, or storage-confirmation rules. In an agent setting, this can cause unintended note capture or file modifications from ordinary conversation, especially because the skill implies persistent local storage and automatic organization.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal