Back to skill

Security audit

Thinking Spark

Security checks across malware telemetry and agentic risk

Overview

This appears to be a local thought-capture skill, but it may save personal notes to disk more broadly than users expect.

Review this skill before installing if you may discuss private ideas, journal-like content, business plans, or confidential drafts. Use it only when you explicitly want persistent notes saved locally, and check or remove collection/思考火花.json if you do not want those records retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is broad enough to capture generic note-taking or idea-organizing requests, which can cause over-activation of a persistent-storage skill in situations where the user only wanted transient assistance. In this context, broad routing increases the chance that ordinary conversation content, including sensitive thoughts or drafts, is stored unexpectedly.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The markdown explicitly defines a persistent JSON storage location for thought records but does not warn users that their inputs will be written to disk. Because the stored content is personal free-form thinking, this omission is especially risky: users may reveal sensitive intellectual, personal, or business information under the assumption the interaction is ephemeral.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.