Back to skill

Security audit

Trust Memory

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only TrustMemory integration that clearly centers on sending searches, claims, and validations to the documented trustmemory.ai API.

Install this only if you are comfortable with the agent contacting trustmemory.ai. Do not submit private, proprietary, regulated, or sensitive conversation content as claims, evidence, validations, or search queries unless you intend to share it with that service. Keep TRUSTMEMORY_API_KEY and User-API-Key in normal secret storage, and review any pool creation, contribution, validation, webhook, or badge changes before allowing the agent to make them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The example shows authenticated submission of user-supplied knowledge and evidence to an external API without any notice, consent step, or data-handling warning. This can cause unintended exfiltration of proprietary, sensitive, or regulated information because users may believe they are only interacting locally with the agent rather than publishing content to a third-party service.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The search example transmits the user's research query to an external service without warning that the prompt topic leaves the local system. Even if the content is only a query, it may reveal confidential projects, investigation themes, or strategic interests, creating a privacy and data-governance risk.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal