Back to skill

Security audit

Language Learning Tutor

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only language tutor with broad capability claims, but no evidence of hidden access, code execution, persistence, or data misuse.

This skill appears safe to install from the reviewed artifacts. Users should treat its universal language-support claims cautiously, especially for low-resource or sign languages, and explicitly request their preferred helper language or an immersion-only format if they do not want English translations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description uses very broad activation cues such as 'learn ANY language' and a long list of generic educational intents like translation, conversation, travel, and pronunciation. This can cause the agent to invoke the skill for loosely related requests, increasing the chance of misrouting, over-collection of user context, or the skill responding outside a narrowly intended scope.

Vague Triggers

Low
Confidence
82% confidence
Finding
Claims to support 'EVERY human language' and 'ANY other language' create ambiguous scope and capability overstatement. In practice, this can trigger the skill for requests it cannot reliably handle, producing unsafe or misleading outputs, especially for low-resource, endangered, sign, or specialized languages where quality may be poor.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.