Back to skill

Security audit

Family Cultivation Coach

Security checks across malware telemetry and agentic risk

Overview

This skill is a family scheduling assistant that handles sensitive child and household details, but its artifacts consistently keep storage and external integrations opt-in and confirmation-based.

Before installing, be aware that the templates can capture sensitive information about a child and household routines. Use nicknames or initials, avoid school names, addresses, contact details, medical details, and exact locations, and only enable Feishu or Notion storage if you understand the destination, retention, and deletion process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template solicits extensive child and household information, including age, school stage, routines, family structure, caregivers, siblings, schedules, and constraints, which can collectively form a sensitive profile of a minor. Even though the broader skill metadata mentions default non-storage behavior, this file itself provides no in-context privacy warning, minimization guidance beyond avoiding a full real name, or notice about how the data should be handled, increasing the risk of oversharing, unsafe retention, or later export to third-party tools.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The template explicitly prompts for sensitive child and parent wellbeing information, including emotional state, fatigue, illness, behavioral difficulties, and parent energy/emotional status, but it contains no inline privacy notice, minimization guidance, retention warning, or caution against sharing/storing this data insecurely. In this skill context, the metadata says data should remain in-session unless the user explicitly enables external storage, which reduces severity, but the template itself can still be copied into external tools or saved by users without any warning.

VirusTotal

49/49 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.