emotional-memo

Security checks across malware telemetry and agentic risk

Overview

This skill openly acts as a local relationship journal, and its sensitive memory behavior is disclosed and aligned with its purpose.

Install only if you are comfortable with relationship details being saved locally in data/memo.json and reused in later conversations. Be deliberate about what you ask it to save, avoid recording secrets or safety-critical details, and periodically review or delete entries you no longer want retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The Record workflow is triggered by broad phrases like 'I felt...' and 'something happened', which can easily occur in ordinary conversation. In this skill, those triggers can cause the agent to extract sensitive emotional data and persist it to `data/memo.json` without a clearly scoped consent check for each save, increasing the risk of over-collection and unintended retention of highly personal relationship information.

Vague Triggers

Low
Confidence
80% confidence
Finding
The Review Timeline workflow is activated by vague terms like 'review' or 'show history', which may match ambiguous requests without making clear whether the user wants the full emotional record surfaced. Because the stored data is intimate and involves two people, loose trigger matching can expose sensitive summaries or patterns in contexts where the user did not explicitly request that level of disclosure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal