Back to skill

Security audit

japanese-n1-sprint-coach

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only Japanese N1 study coach with some overly broad triggers, but no code, credential access, persistence, or data-exfiltration behavior.

Install this if you want a structured Chinese-language JLPT N1 coach. Be aware it may trigger on broad Japanese-learning terms and may refuse full translations, so invoke it intentionally for N1 exam-prep tasks rather than general translation or casual language questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list is broad enough to match many common Japanese-learning interactions such as '翻译', '语法', and '阅读', which can cause the skill to activate when the user did not explicitly request this specific coach. That increases the chance of response hijacking or unintended workflow interference, especially in environments with multiple installed skills competing on generic educational terms.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The description states the skill will output a fixed style/content format without indicating user language preference or opt-in, which can override user expectations and reduce usability in multilingual contexts. While not a classic security flaw, forced output behavior can contribute to prompt-control issues by making the skill less responsive to explicit user preferences and system routing expectations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger set includes many generic language-learning terms such as '语法', '词汇', '阅读', and '翻译', which are common in unrelated conversations and can cause the skill to activate outside its intended JLPT N1 scope. Unintended activation can override a more appropriate skill or force restrictive behavior like refusing full translation, degrading user experience and creating routing/priority issues in multi-skill environments.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation logic relies on broad keyword matching like 'contains Japanese characters' or presence of study-related terms, without exclusions or confidence thresholds. This makes the skill prone to accidental triggering on arbitrary Japanese text, translation requests, or general discussions, which can misroute requests and apply the skill's rigid response rules where they do not belong.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
89% confidence
Finding
The trigger 'N1' is extremely short and ambiguous, so it may match unrelated text such as model names, codes, or shorthand not referring to the JLPT exam. Even though the skill is educational, such a short trigger increases accidental invocation risk in shared routing systems.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding
The trigger '语法' is a broad everyday term used across many languages, education contexts, and even metaphorical discussions. On its own, it can activate the skill for requests unrelated to Japanese or JLPT N1, causing unintended routing and inappropriate response constraints.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding
The trigger '词汇' is generic and commonly appears in broad education or language tasks unrelated to this skill's narrow scope. This can cause accidental activation and lead the skill to impose N1-oriented output on general vocabulary requests.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
94% confidence
Finding
The trigger '阅读' is too general and may match any reading-related request, including non-language-learning or non-Japanese tasks. In a multi-skill environment, this broad match can unnecessarily divert unrelated requests into this skill.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
94% confidence
Finding
The trigger '听力' is a common term for listening practice across many subjects and languages, making it too broad for reliable activation. This increases the chance of accidental skill invocation and mismatched educational guidance.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
93% confidence
Finding
The trigger '备考' is a generic exam-preparation term applicable to many tests, certifications, and school contexts. Without narrower qualifiers, it can cause the skill to activate for unrelated exam planning requests.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
The trigger '日文' indicates Japanese language broadly, but not necessarily N1 exam prep or the specialized behavior of this skill. It may still over-match general Japanese translation or casual language questions and route them into an overly restrictive coaching workflow.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding
The trigger '翻译' is especially broad and conflicts with the skill's own rule to refuse full translation, making accidental activation more likely on requests the skill is not designed to serve. This mismatch can frustrate users and interfere with correct tool or skill selection.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding
The trigger '语感' is a vague, cross-domain term used in many language and writing discussions. As a standalone activator, it lacks the specificity needed to safely route only N1-focused Japanese learning requests.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
94% confidence
Finding
The trigger '助词' is common in Japanese study but still broad enough to match general beginner/intermediate grammar questions outside N1 sprint coaching. This can lead to over-activation and force advanced-exam framing on lower-level or unrelated requests.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
94% confidence
Finding
The trigger '文法' is another broad grammar-related term that can capture a wide range of Japanese and non-Japanese requests. In context, the risk is not code execution or data exposure, but unintended activation and policy misapplication.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.