Back to skill

Security audit

treeline

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for a finance assistant, but it tells agents to persist reusable facts about a user’s finances without clear opt-in or retention limits.

Install only if you are comfortable giving the Treeline CLI and agent access to your local finance database. Before using it with real data, set a boundary that the agent should not store financial memories unless you explicitly approve each one, and review write actions such as imports, syncs, restores, tagging, or write-enabled SQL before confirming them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to retain reusable facts about the user's finances for future conversations. Financial preferences, account meanings, and spending conventions are sensitive personal data, and persisting them beyond the immediate task increases privacy risk, cross-context leakage risk, and the chance of unauthorized reuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.