Back to skill

Security audit

English Reading Coach

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only English reading tutor skill with no code execution or credential access; its main cautions are broad activation wording and optional web fetching for lesson texts.

Install this if you want an agent to run structured English reading lessons and fetch public passages for practice. Be aware it may activate on casual requests for something to read in English, and only connect it to a daily cron workflow if you intentionally want recurring reading drills. State your preferred explanation language if you do not want Vietnamese framing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Confidence
96% confidence
Finding
The README instructs the skill to trigger on a very wide range of common, casual phrases, including generic requests like asking for something to read or to practice today. In an agent environment, this can cause unintended invocation and context hijacking, where the skill activates when the user did not explicitly ask for a structured English-reading coaching workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases remain broad and do not define boundaries for when the skill should not activate. Without limiting context, an orchestrating agent may over-match everyday educational or reading-related requests and route them into this skill unnecessarily.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The starter prompts are generic enough to overlap with normal user requests that do not necessarily imply consent to a full skill workflow. This increases the chance of accidental activation, especially in systems that use examples as matching signals for routing.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description is extremely broad and explicitly includes casual phrases like 'give me something to read in English' and 'let's practice reading today,' which can cause the skill to activate in situations where the user did not intend a full reading-coach workflow. Over-broad invocation increases the chance of misrouting user requests, unnecessary web fetching, and unexpected behavior that overrides a more appropriate skill or default assistant response.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The instruction to keep framing in Vietnamese 'when helpful' introduces unsolicited language switching without confirming the user's preferred language. This can create policy and UX issues by presenting content in a language the user did not request, which may reduce comprehension or violate locale expectations in multilingual contexts.

VirusTotal

2/65 vendors flagged this skill as malicious, and 63/65 flagged it as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.