Back to skill

Security audit

Hume Network

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent, but it asks an agent to monitor local activity, run persistent collectors, and share derived patterns to a public network, so users should review it carefully before installing.

Install only if you are comfortable with a networked tool observing local workflow patterns and sharing derived, anonymized summaries. Review the external npm packages first, avoid daemon and auto-propose modes unless you explicitly want continuous monitoring, and manually approve anything sent to the network.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages running persistent collectors and daemon mode that observe developer and system activity, but it does not present a clear, upfront warning about continuous monitoring before those features are invoked. In a skill whose purpose is to mine local workflow patterns, missing explicit notice and consent creates a real privacy risk because users may enable background collection without understanding the scope and persistence of observation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes proposing patterns to the network and syncing with a hub, but it does not clearly warn users that derived observations leave the device and are shared with an external service. Even if the data is intended to be anonymized, off-device transmission of behavior-derived telemetry is security- and privacy-sensitive, especially in enterprise or regulated environments.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.