Back to skill

Security audit

AI钢琴老师

Security checks across malware telemetry and agentic risk

Overview

This is a static piano-tutoring skill whose broad triggers may cause occasional misrouting, but its behavior is disclosed, educational, and low impact.

Safe to install for piano-learning help. Be aware it may activate on broad Chinese music terms, share only learner details you are comfortable using for personalization, and review any generated HTML or Tencent Docs report before sharing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes short, common educational phrases that can match routine conversation outside an explicit request to invoke this skill, increasing the chance of unintended activation. In an agent environment, accidental invocation can disrupt normal routing, produce irrelevant responses, and cause the assistant to collect extra learner-profile information when the user did not intend to enter this skill.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The fallback rule for '综合咨询' activates on vague phrases like '怎么开始' or when there is no clear direction, which is too permissive for a user-invocable skill. This can cause the skill to take over generic educational or self-improvement conversations and start probing for age, goals, and practice habits without sufficiently clear piano context.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
83% confidence
Finding
The trigger '乐理' is a very short and generic term that can appear in broad music discussions, homework help, or metadata unrelated to invoking this specific piano-teacher skill. Such low-specificity triggers increase accidental activation risk and can interfere with correct tool or skill routing.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
81% confidence
Finding
The trigger '视奏' is short and context-agnostic, so it may match unrelated music conversations or broader educational requests not meant for this skill. This mainly creates misrouting and unintended invocation rather than direct system compromise.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
81% confidence
Finding
The trigger '练耳' is similarly broad and can appear in generic music-study contexts beyond piano instruction, making unintended invocation plausible. In this skill's context the consequence is limited, but it still weakens routing precision and user intent matching.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.