JournalBot Daily Journaling with AI Prompts

Security checks across malware telemetry and agentic risk

Overview

This journaling skill stores entries locally as markdown files and shows no evidence of hidden network access, credential use, or destructive behavior.

Install only if you are comfortable with personal journal entries being saved as local markdown files, likely unencrypted by default. Keep the journal folder in a private location, avoid writing secrets you would not want stored on disk, and consider backups or encryption if the device is shared or synced.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill explicitly stores highly personal journal content in local markdown files, but it does not meaningfully warn users that these reflections may contain sensitive mental-health, relationship, work, or other private data that could be exposed through shared devices, backups, indexing, or weak filesystem permissions. In a journaling skill, this omission matters because users are likely to disclose intimate information under an assumption of privacy.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal