Back to skill

Security audit

Proactive Agent

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate proactive-agent template, but it asks agents to remember, monitor, and change too much by default without enough consent controls.

Install only if you explicitly want a persistent proactive agent. Before use, require opt-in for memory/profile logging, define which mailboxes, calendars, files, apps, logs, tools, and accounts it may access, disable or approve crons and autonomous sub-agents, and review or purge the memory files it creates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The file mixes strong autonomy cues such as 'Don't ask permission. Just do it.' with later safety rules that require asking before destructive, uncertain, or external actions. This ambiguity can cause an agent to choose the more permissive interpretation and act without appropriate user consent on impactful tasks.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill authorizes web and calendar access 'freely' while also saying to ask first for anything that leaves the machine. In practice, web and calendar operations often involve outbound network access and third-party services, so this contradiction can normalize silent data disclosure or account interaction without user awareness.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The heartbeat checklist broadens the agent’s authority from proactive assistance into endpoint/workspace management tasks such as closing apps, pruning tabs, and deleting files. In an autonomous or semi-autonomous agent, this creates a real risk of unintended state changes, workflow disruption, or data loss that is not clearly tied to the declared skill purpose.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The instructions to close applications, close browser tabs, and move screenshots to trash authorize potentially destructive actions without establishing user consent, safety checks, or necessity for the proactive-agent function. This can interfere with active work, discard unsaved state, or remove files the user still needs.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Periodic checking of emails, calendar, and projects expands the skill into routine surveillance of privacy-sensitive data sources beyond what is necessary for the stated feature set. If enabled broadly, it normalizes continuous access to personal and business information and increases the blast radius of any prompt misuse or agent error.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The onboarding reference expands from profile collection into generalized proactive behavior such as checking in, looking for ways to help, and building things the user may find useful. That broadens the agent’s operational scope beyond onboarding and can normalize autonomous actions without clearly bounded authorization, which increases the risk of unintended actions or unsafe delegation in downstream implementations.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The promise to 'always check before doing anything external' is a weak safeguard because the surrounding language encourages proactive helping and building without defining what counts as external or what approval is required for internal but impactful actions. This inconsistency can mislead users and implementers into believing sufficient safeguards exist when they do not.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill repeatedly frames the agent as broadly proactive in normal conversation without narrowly defined triggers, boundaries, or approval gates for when proactive behaviors should occur. In practice, this can cause unintended actions, overreach, and user-surprising behavior, especially when combined with memory, check-ins, and automation features elsewhere in the file.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The quick-start and onboarding flow instruct the agent to automatically populate persistent profile files like USER.md and SOUL.md from user answers, but there is no clear retention notice, consent flow, or explanation of what data will be stored. This creates a privacy and profiling risk because users may disclose personal information without understanding that it will be retained across sessions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The onboarding guidance encourages gradual collection of personal information over time and opportunistic learning from conversation, but it does not pair this with meaningful privacy disclosure or consent boundaries. That makes the elicitation more risky because the user may not realize a conversational answer is being turned into durable profile data.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The WAL trigger instructs the agent to scan every user message for broad categories like corrections, preferences, decisions, and specific values. That creates an always-on behavioral hook that can activate on routine conversation and drive automatic persistence, increasing the chance of over-collection and unintended handling of sensitive content.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The quick-start flow says the agent will auto-populate persistent files like USER.md and SOUL.md from user answers, but it does not present a clear consent notice about durable storage of conversation data. This can cause users to disclose personal information without realizing it will be written to workspace files and retained beyond the session.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The WAL trigger is intentionally broad and fires on common conversational elements like corrections, names, preferences, and specific values. In practice this causes pervasive activation and automatic persistence of user content, increasing the chance that sensitive data is written to disk without meaningful user awareness or consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section instructs the agent to write many categories of user-provided information to SESSION-STATE.md immediately, but the skill’s top-level description does not clearly warn users that conversation content will be persistently logged to workspace files. That omission undermines informed consent and can expose sensitive information to other tools, users, or future sessions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill endorses autonomous background work via isolated agentTurn crons but does not prominently disclose that behavior in the primary description or require explicit enablement. Hidden or under-disclosed autonomy can surprise users and lead to unreviewed actions, file modifications, or recurring processes in the workspace.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instruction to follow BOOTSTRAP.md and then delete it directs file deletion without a user-facing confirmation step, directly conflicting with later deletion-confirmation guidance. A malicious or mistaken BOOTSTRAP file could cause harmful setup actions and then erase evidence or auditability by deleting itself.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
Mandating that the agent read SOUL.md, USER.md, daily memory, and MEMORY.md every session creates unconditional access to potentially sensitive profile and history data regardless of task relevance. This violates data minimization and increases the chance of unnecessary exposure, over-collection, and prompt-context leakage into later actions.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file instructs the agent to close apps, close browser tabs, and move screenshots to trash without any warning about unsaved work, interruption risk, or accidental deletion. In a heartbeat context, these actions may occur repeatedly and automatically, making even benign mistakes operationally harmful.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The encouragement to periodically inspect email, calendar, and project data lacks any privacy warning, consent model, or scope limitation despite involving highly sensitive personal and organizational information. This makes the guidance unsafe in contexts where the agent may autonomously poll or summarize those sources.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The template explicitly prompts storing sensitive personal information such as background, preferences, and important dates, but provides no privacy notice, consent guidance, retention limits, or data minimization controls. In a long-term memory file for an agent, this can normalize unnecessary collection and persistence of personal data, increasing privacy and compliance risk if the memory is exposed, misused, or retained too long.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The 'Relationships & People' section encourages storing information about third parties, including their relationship to the user and relevant context, without any warning about third-party privacy, consent, or sensitivity. This is risky because an agent may accumulate personal details about people who never agreed to collection, creating avoidable privacy exposure and potential misuse.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This onboarding flow explicitly solicits sensitive personal context such as timezone, work projects, key people, goals, and preferences, and states that the agent will persist that information into local files like USER.md and SOUL.md. The file does not provide a clear privacy warning, consent language, data minimization guidance, or retention limits, which creates a real risk of over-collection and unintended storage of personal data in plaintext within the skill workspace.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document explicitly directs users to document credential locations and gives a concrete secrets directory pattern without any warning about secrecy, access controls, or avoiding disclosure of sensitive paths. In a proactive-agent skill, notes like this may be repeatedly consulted or propagated by an agent, increasing the chance that secret file locations are surfaced in prompts, logs, summaries, or commits, which can aid credential discovery and misuse.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This template explicitly solicits personal profile data, goals, relationships, preferences, and free-form notes without any minimization guidance, retention limits, or warning not to include sensitive information. In an agent skill designed to build ongoing user context, that creates a real privacy risk because users may over-share sensitive personal or relationship data that can later be exposed, misused, or inappropriately propagated into prompts and memory.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The guidance instructs the agent to save user answers into persistent profile files immediately after each response, but it does not require disclosure, consent, retention limits, or any notice that the data will be stored across sessions. That creates a privacy vulnerability because users may reveal personal information in a conversational context without understanding it is being recorded long-term.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
assets/HEARTBEAT.md:11

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/security-patterns.md:9

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL-v2.3-backup.md:179