Maintenance

Security checks across malware telemetry and agentic risk

Overview

This is a local home-maintenance logging tool, and its persistent local storage matches what it says it does.

Install only if you are comfortable keeping maintenance notes, appliance details, schedules, costs, and exports in local files under ~/.local/share/maintenance. Avoid entering secrets or access codes, protect backups of that directory, and delete old logs or export files manually when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly advertises automatic history and activity logging for home maintenance data, which may include sensitive household details such as appliance inventories, schedules, repairs, and occupancy patterns. Failing to clearly warn users about retention and privacy implications can lead to unintended local exposure, especially on shared machines, in backups, or through overly permissive filesystem access.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script automatically creates a persistent data directory under the user's home directory and stores all entered content and exports there, but it does not provide any upfront notice or consent mechanism before retention begins. Because the tool accepts free-form input for many commands, users may enter sensitive household, scheduling, inventory, or cost information without realizing it will be written to disk and retained in multiple files.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal