Back to skill

Security audit

daily-viz

Security checks across malware telemetry and agentic risk

Overview

This is a simple daily tracking skill that stores user-entered habit and wellness data locally, with no evidence of hidden upload, credential access, or destructive behavior.

Install only if you are comfortable storing personal wellness and productivity records in a local JSON file under your home directory. Treat export, share, cloud-sync, and encryption claims as under-specified unless a future version clearly explains what leaves the device, where it is stored, and how deletion works.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill says data is stored under ~/.daily-viz/data/ and supports export/import, but it does not clearly warn users that normal use will create persistent files in their home directory. This can surprise users on shared systems or privacy-sensitive environments, especially because the stored content includes personal habit and health-related data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises optional cloud sync for personal mood, sleep, exercise, and work-habit data without warning that sensitive personal information may leave the device. Users may reasonably rely on the nearby privacy claims and underestimate the exposure, creating a risk of unintended disclosure or noncompliant handling of sensitive data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal