Back to skill

Security audit

Lightweight Knowledge Base

Security checks across malware telemetry and agentic risk

Overview

This is a local knowledge-base skill that stores and updates profile/task data on disk, with no evidence of hidden network transfer or destructive behavior.

Install only if you want a local persistent memory and task-management system. Before use, review or reset data/user_profile.json, disable enabled daily or deep-dialogue tasks in data/task_rhythm.json if you do not want recurring updates, and avoid storing API keys or sensitive personal details in indexed memory files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly advertises '每日进化' and automatic user profile optimization, which implies persistent modification of stored personal data and knowledge records without a clear consent, notice, or review step. In a memory-management skill, silent background updates can alter sensitive profile data, create inaccurate inferences, and reduce user control over retained information.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The initialization step instructs creation of persistent files and directories but does not clearly warn the user that local storage will be created and populated. While expected for a knowledge-base skill, undisclosed file creation can surprise users, pollute workspaces, or cause unintentional persistence of potentially sensitive information.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The scheduling rules combine automated execution with broad natural-language recovery behavior such as "missed tasks are re-executed in the next cycle" and flexible skip conditions. Without precise constraints on when deferred tasks may run, the skill could trigger actions unexpectedly or at inappropriate times, which is risky when tasks include profile updates or knowledge-base modifications.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The document is entirely written in Chinese and defines communication norms in Chinese without indicating that users can choose another language or opt in to Chinese-first interaction. In a user-facing skill, this can cause exclusion, misunderstanding of instructions, and reduced transparency or informed consent for users who expect another language, especially when the skill manages tasks and knowledge that may contain important personal context.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The guidance explicitly retrieves and uses user profile data to shape task execution, but it provides no privacy notice, purpose limitation, consent check, or handling constraints. In an agent skill, this can lead to over-collection or inappropriate use of personal preference/trait data across tasks without the user's informed awareness.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow instructs the agent to record execution details into a case library, which may store user activity, requests, and inferred patterns indefinitely without warning or approval. That creates a privacy and data-retention risk because task history can accumulate sensitive behavioral information and be reused in later contexts beyond the user's expectation.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The acceptance/checklist language requires creating outputs and updating knowledge indexes, but it does not warn that files will be modified or define safeguards around what may be written. In a memory-management skill, silent file writes can unexpectedly persist user content, amplify privacy issues, and make unintended changes harder to audit or reverse.

Ssd 3

Medium
Confidence
94% confidence
Finding
The weekly task explicitly schedules a "natural conversation" to collect user information and update a user profile, which creates a privacy and consent risk if performed automatically. Automated or routine profiling can lead to over-collection of personal data, inaccurate inferences, and retention of sensitive information without clear user awareness or opt-in.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.