Adaptive Memory

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local workspace memory skill that creates and updates memory files, with no evidence of hidden collection, network access, or unsafe installation behavior.

Install this only in workspaces where you want the agent to keep durable local notes. Do not put secrets, tokens, passwords, or sensitive client data in the memory files, and consider using version control or backups before allowing automatic distillation or pruning.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The session-start routine instructs the agent to automatically read multiple local memory files before responding, without requiring explicit user consent or warning that those files may contain sensitive workspace data. In environments where file access is powerful, this can lead to unnecessary exposure of private project context and normalization of implicit workspace-wide data access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal