Security audit
colleague-skill
Security checks across malware telemetry and agentic risk
Overview
This skill openly collects workplace chats and documents to build persistent coworker personas, but it requests broad account tokens and can perform account/API actions without clear scoping or confirmation.
Install only if you are authorized to collect and process the relevant coworker/workspace data. Use least-privilege, preferably read-only app credentials; avoid DM/private-channel collection unless absolutely necessary; require explicit approval before any API action that sends or modifies data; review generated skills before invoking them; and delete local token/config, knowledge, and version archives when finished. No hidden exfiltration endpoint is evident in the provided artifacts, but the documented access level is broad enough to require careful review.
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
