Kindergarten Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only early-childhood teaching assistant with privacy-sensitive memory fields, but no executable or hidden behavior.

Safe to install for planning and documentation, but treat its memory as sensitive. Avoid unnecessary identifying details, get appropriate parent or guardian consent, follow school childcare and privacy policies, restrict access to stored notes, and periodically review or delete child and family records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly states it maintains child profiles, developmental observations, parental communication, and other records about infants and toddlers, but it provides no warning about consent, data minimization, retention, or safeguarding obligations. Because this concerns highly sensitive information about very young children, the omission creates a real privacy and compliance risk if users are encouraged to store personally identifiable or developmental data without appropriate controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal