Remembering Conversations

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed conversation-memory skill whose sensitive access is expected for searching past work, but users should treat past-chat retrieval as privacy-sensitive.

Install only if you want your agent to search prior conversations. Before using it, assume past chats may contain secrets, credentials, personal data, tool outputs, or private project details, and use the narrowest search/read scope that answers the current question.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documented `read` capability allows retrieval of full historical conversations, including user/assistant content, tool invocations, and tool results, which can expose sensitive data from prior sessions. In a skill specifically designed to search past work, this is contextually expected functionality, but the absence of documented privacy constraints, consent requirements, or minimization guidance increases the risk of over-collection and unintended disclosure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal