学习指南网页生成器

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk template for turning study materials into interactive HTML pages, with one usability caveat around broad auto-trigger wording.

Before installing, be aware that this skill may activate for a broad range of requests about turning notes, exam material, or teaching content into webpages. Review generated HTML before publishing, especially external CDN links and any subject-matter content, but the artifacts do not show hidden data access or unsafe behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill declares very broad trigger conditions and explicitly says it must be forcibly used even when the user does not clearly request a study guide. That creates an overreach risk where the agent may invoke this skill in unrelated contexts, override user intent, and route content into HTML generation unnecessarily, which can degrade safety controls and increase the chance of mishandling sensitive or inappropriate inputs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal