focusnoteapp

Security checks across malware telemetry and agentic risk

Overview

This skill appears to perform the stated FocusNote task: append user-provided text to a local daily note, with no evidence of hidden networking, credential theft, or destructive behavior.

Install this only if you want the assistant to write into your local FocusNote daily notes. For ambiguous requests, ask it to confirm the exact text and that it should append to today's FocusNote daily note before running the helper script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The skill performs immediate local file creation and modification under a user-derived documents path without any explicit warning, confirmation step, or stated consent boundary. In an agent setting, this increases the risk of unintended persistence of sensitive or incorrect content to disk, especially if the skill is invoked from ambiguous natural-language requests.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal