Back to skill

Security audit

日语会话测试批改

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Japanese conversation grading aid, but users should handle optional platform integrations and student data carefully.

Before installing, confirm your school permits AI-assisted processing of student audio and grades. Keep API tokens in local config or environment variables only, prefer the default CSV workflow unless an adapter has been reviewed, and require teacher confirmation before posting grades or feedback to any course platform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The skill explicitly supports optional adapters and scripts that can pull submissions and push feedback or grades to external platforms, which expands its security and privacy attack surface. Even though the document says tokens should be stored locally, it still describes handling student identifiers, audio, grades, and feedback through external APIs without clear permission boundaries, least-privilege guidance, or safeguards against misdelivery and overcollection.

Description-Behavior Mismatch

Medium
Confidence
76% confidence
Finding
The documentation markets the skill as platform-independent and unbound, but the described workflow includes direct platform API operations such as pulling submissions and posting results. That mismatch can cause operators to underestimate the trust boundary and deploy the skill in environments where external writes, grade changes, or student-data transfers are not expected or properly reviewed.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill describes automated retrieval of student submissions and delivery of per-student feedback through external course-platform APIs, but it does not address privacy, consent, retention, access control, or regulatory handling of student data and grades. Because the processed data includes names, IDs, audio recordings, transcripts, and assessment results, insufficient privacy guidance materially increases the risk of unauthorized disclosure or misuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.