Lunar Reminder

Security checks across malware telemetry and agentic risk

Overview

This skill transparently manages local Chinese lunar-calendar reminders and scheduled reminder notifications, with no evidence of hidden data access or harmful behavior.

Install only if you are comfortable storing reminder details locally in the skill directory and using Asia/Shanghai as the reminder timezone. Use simple reminder names, avoid sensitive notes, and periodically review synced cron jobs because they can continue firing until removed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill includes direct scheduler management commands that create and remove cron jobs using event names interpolated into command arguments. In this context, reminder management can justify scheduling, but exposing raw cron administration without clear validation, escaping, or least-privilege boundaries increases the risk of command/argument injection or unintended persistent task creation.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal