Oathe Security Badge

Is novyxlabs/novyx-reflect safe?

https://github.com/novyxlabs/novyx-reflect

93
SAFE

Novyx Reflect is a legitimate memory management skill that provides agent memory optimization features. The code is clean with no malicious behavior detected, proper safety guardrails, and standard library patterns. The only concern is legitimate external API communication with Novyx servers.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 85/100 · 25%
Code Execution 95/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (1)

LOW External API Communication -15

The skill communicates with external Novyx API endpoints for memory management functionality. While legitimate for its stated purpose, this involves sending data to third-party servers.