Plant

Security checks across malware telemetry and agentic risk

Overview

This is a local plant-care logging tool that saves entries on the user's machine and does not show hidden network access or destructive behavior.

Install only if you are comfortable with plant notes, schedules, costs, and activity history being saved locally under ~/.local/share/plant. Avoid entering passwords or unrelated sensitive information, and remove that directory manually if you want to delete the stored data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The script persistently stores all user-provided inputs and an activity history under ~/.local/share/plant without clearly warning the user that their entries will be retained on disk. Because many commands accept arbitrary free-form text, users may enter sensitive household, schedule, cost, or personal information that remains locally exposed to other processes or users with access to the account.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal