Back to skill

Security audit

Proactive Agent

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent about being a proactive memory-based agent, but it asks for broad persistent logging, profiling, autonomous work, and tool use that need careful review before installation.

Install only if you want an agent that keeps durable workspace memory and proactively reads, organizes, and updates local context. Before using it, set clear limits: do not store secrets or sensitive personal details, require approval for calendar/web/account access and spawned agents, review the memory files regularly, and define how to delete or prune retained logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill markets itself as a proactive-agent architecture, but it also instructs users to run a local security audit script and the static finding indicates broader auditing behavior than the description discloses. That mismatch is dangerous because users may install or trust the skill for productivity features while overlooking security-relevant file inspection behavior, reducing informed consent and increasing the chance of overbroad local data access.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill explicitly pushes broad, execution-heavy behavior beyond proactive memory management by telling the agent to try many methods and use CLI, browser, web search, and spawned agents. In a general-purpose agent, this expands attack surface and can turn ambiguous user or external content into unsafe tool use, especially when paired with its proactive/autonomous framing.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
The skill recommends creating a weekly cron reminder, introducing persistent autonomous behavior not clearly justified by the stated purpose of proactive memory and security patterns. Scheduled activity can cause unsupervised actions, unexpected data processing, or repeated outreach without contextual approval.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill gives the agent broad permission to read files, search the web, and check calendars 'freely' while separately stating that anything leaving the machine requires asking first. That ambiguity can cause an agent to treat networked actions as implicitly authorized, leading to unintended external data disclosure or access to third-party services without explicit user consent.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The instruction to update AGENTS.md, TOOLS.md, or skill files immediately after a lesson learned can override the separate rule forbidding unapproved security changes. In practice, an agent may classify policy, guardrail, or tool-behavior edits as routine self-improvement and make sensitive changes without human review.

Ssd 3

Medium
Confidence
95% confidence
Finding
This section explicitly instructs the agent to collect, persist, and update personal context about the user across sessions via ONBOARDING.md, USER.md, and SOUL.md. That creates durable retention of potentially sensitive user data without any stated minimization, consent boundaries, retention limits, or classification rules, which increases privacy and secondary-use risk if the workspace is exposed or reused.

Ssd 3

Medium
Confidence
97% confidence
Finding
The memory flush protocol tells the agent to write 'everything important' and anything needed to continue the conversation into durable notes, which can capture broad conversational content and reasoning trails. This is dangerous because it encourages indiscriminate retention of user data and contextual details that may include secrets, sensitive business information, or personal matters beyond what is necessary.

Ssd 3

Medium
Confidence
94% confidence
Finding
Describing daily logs as capturing relevant session information continuously promotes ongoing accumulation of raw user interaction data in dated files. Raw logs are especially risky because they tend to preserve more detail than curated summaries, increasing exposure if accessed by other tools, agents, or users.

Ssd 3

Medium
Confidence
94% confidence
Finding
The onboarding flow directs the agent to collect user answers and auto-populate persistent profile files, creating durable storage of potentially sensitive personal information. This increases privacy risk, over-collection, and the chance that future prompts, tools, or other skills will expose or misuse retained data.

Ssd 3

Medium
Confidence
97% confidence
Finding
The WAL protocol instructs the agent to persist a wide range of user-provided details before responding, including specific values, IDs, and URLs. This creates systematic retention of sensitive data and secrets in plaintext state files, magnifying leakage risk through later reads, logs, backups, or compromised tools.

Ssd 3

High
Confidence
99% confidence
Finding
The Working Buffer mandates recording every user message and agent summary after a context threshold, effectively creating a raw transcript store. This is a significant data retention and privacy risk because it captures incidental sensitive content wholesale, not just necessary task state, and preserves it specifically during high-context periods when conversations may be most detailed.

Ssd 3

Medium
Confidence
88% confidence
Finding
Compaction recovery instructs the agent to reread raw stored exchanges to reconstruct context, reinforcing dependence on retained transcripts and increasing the chance sensitive historical content will be surfaced or reused unexpectedly. The risk is amplified because the procedure normalizes broad retrieval from prior conversations rather than limiting recovery to curated state.

Ssd 3

Medium
Confidence
90% confidence
Finding
The growth loop encourages the agent to ask questions to learn more about the user and then log those learnings to a persistent profile. This incentivizes ongoing profiling and accumulation of personal data beyond immediate task needs, increasing privacy, compliance, and secondary-use risks.

Ssd 3

Medium
Confidence
95% confidence
Finding
This section directs comprehensive persistence of conversation content into working-buffer files, including human messages and agent summaries after a context threshold. Persisting broad conversational data increases privacy risk, creates a larger sensitive-data footprint on disk, and can retain secrets or personal information far beyond what is necessary for task continuity.

Ssd 3

Medium
Confidence
97% confidence
Finding
The WAL protocol tells the agent to scan every message for corrections, names, preferences, decisions, IDs, URLs, and other specific values, then write them to persistent state before responding. This creates systematic collection of potentially sensitive personal and operational data, increasing exposure if the workspace is shared, synced, later exfiltrated, or reused by other tools.

Ssd 3

Medium
Confidence
94% confidence
Finding
The onboarding flow encourages gathering personal information over time and auto-populating persistent USER.md and SOUL.md files from user answers. Auto-collecting and storing profile data without clear minimization or consent controls can lead to unnecessary retention of sensitive personal context and increases the consequences of local compromise or accidental sharing.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to extract personal details from ordinary conversation and persist them to USER.md outside a formal onboarding flow. This creates a privacy and data-minimization risk because users may not realize incidental remarks about location, preferences, relationships, or projects are being stored and reused across sessions.

Ssd 3

Medium
Confidence
94% confidence
Finding
The onboarding flow requires saving every answer and copying it into persistent profile files, which may include personal preferences, goals, and other identifying information. Persisting all responses by default increases privacy exposure, retention risk, and the chance of over-collection without granular consent or sensitivity checks.

Ssd 3

Medium
Confidence
88% confidence
Finding
The completion step directs the agent to summarize accumulated identity and context details including name, timezone/location, project, goals, communication style, and key people. Consolidating and restating these details increases exposure of a user profile in one place and can leak more sensitive context than necessary if shown in the wrong context or stored in logs.

Scope Creep

Low
Category
Excessive Agency
Content
- Preferences: Work style, communication, decision-making
- Relationships: Key people, who matters
- Values: What they optimize for, dealbreakers
- Aspirations: Beyond stated goals, what does ideal life feel like?

### Making It Actually Happen
Confidence
76% confidence
Finding
Beyond stated

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
1. Try a different approach immediately
2. Then another. And another.
3. Try 5-10 methods before considering asking for help
4. Use every tool: CLI, browser, web search, spawning agents
5. Get creative — combine tools in new ways

### Before Saying "Can't"
Confidence
93% confidence
Finding
Use every tool

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
1. Try a different approach immediately
2. Then another. And another.
3. Try 5-10 methods before considering asking for help
4. Use every tool: CLI, browser, web search, spawning agents
5. Get creative — combine tools in new ways

### Before Saying "Can't"
Confidence
88% confidence
Finding
Use every tool

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
1. Try a different approach immediately
2. Then another. And another.
3. Try at least 5-10 methods before asking for help
4. Use every tool: CLI, browser, web search, spawning agents
5. Get creative — combine tools in new ways

**Pattern:**
Confidence
91% confidence
Finding
Use every tool

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
assets/HEARTBEAT.md:11

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/security-patterns.md:9

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL-v2.3-backup.md:179