Back to skill

Security audit

Data Prompt Coach 数据分析Prompt引导教练

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent about being a data-analysis prompt coach, but it can rewrite its own method/routing files and generate persistent automation artifacts, so it deserves manual review before install.

Install only if you are comfortable with a skill that can edit its own method library and routing files. Review diffs after any tutorial distillation, avoid uploading raw sensitive resumes/contracts/invoices unless necessary, redact samples where possible, and manually review any generated .bat scripts, caches, or clear-and-rewrite sync workflows before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill contains contradictory behavior boundaries: it claims '不写代码' and '只产出 Prompt 文本 + 附加交付物模板', yet earlier sections explicitly instruct generating code-like artifacts such as validation scripts, SQL files, JSON Schema, chart code, .bat templates, and an optional SQLite sample DB. This inconsistency can mislead reviewers and downstream agents about what actions and artifacts are permitted, increasing the chance that executable or unsafe content is produced under a narrower claimed safety model.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase '我有一堆简历' is conversational and semantically broad, so normal user messages could trigger the skill unintentionally. Because the skill then enters a guided workflow that may request uploads, inspect documents, write templates, or route into broader analysis behavior, accidental activation expands data exposure and action scope without a deliberate opt-in.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase '我有一堆简历' is conversational and semantically broad, so normal user messages could trigger the skill unintentionally. Because the skill then enters a guided workflow that may request uploads, inspect documents, write templates, or route into broader analysis behavior, accidental activation expands data exposure and action scope without a deliberate opt-in.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The broad Entry A trigger phrases are susceptible to accidental activation on ordinary user requests, which can cause the skill to take over conversations or steer users into unintended workflows. In an agent setting, overbroad prompt routing increases the chance of mis-scoping actions, collecting unnecessary data, or bypassing more appropriate specialized skills.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The distillation trigger wording is overly broad, so unrelated requests could invoke the methodology-distillation path without clear user consent. This kind of unintended activation is dangerous because it can mis-handle content, route sensitive material into the wrong processing flow, and make downstream behavior less predictable in multi-skill environments.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill instructs the agent to create and modify multiple repository files, including routing metadata and test assets, without requiring explicit user confirmation before performing those writes. In an agent setting, that can lead to unauthorized workspace changes, persistence of unreviewed content, and accidental propagation of malformed or unsafe instructions into other files.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The example explicitly describes creating and updating multiple repository files as part of the skill workflow, but it does not mention requiring explicit user confirmation or warning that local files will be modified. In an agent setting, undocumented write behavior can lead to unintended repository changes, especially because the skill also updates indexes, routing matrices, and test files automatically.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs analysis of uploaded Excel/CSV data and extraction of per-column sample values, missingness, duplicates, and outliers, but provides no privacy guardrails for personal or confidential data. In the stated use cases, uploaded tables may contain resumes, contact details, salary data, or other PII, so echoing sample values or profiling fields can unnecessarily expose sensitive information in prompts, logs, or downstream outputs.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad everyday-language terms such as '抓数据' and '批量提取', which can cause the skill to activate in situations the user did not intend. In an agent system, overbroad routing increases the chance of prompt hijacking, context confusion, or unsafe execution paths being entered for ordinary requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger examples include very broad, common data-volume phrases such as "1500 行", "5000 条", and "10 万行", which can appear in ordinary user requests unrelated to this specific skill. This raises the chance of unintended skill invocation, causing the agent to steer users into local scripting or data-processing workflows they did not ask for.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases include very broad, common analytical utterances such as '深入分析', '下钻', and '再看看其他维度'. In a general data-analysis environment, these can cause the skill to activate during ordinary conversation and steer the session into its own workflow, creating prompt-scope hijacking and unintended behavior rather than a narrowly scoped invocation.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger section uses broad natural-language cues such as asking why a conclusion was reached or wanting to validate logic, which can cause the skill to activate in many unrelated analysis contexts. In an agent setting, overly broad activation increases the chance of unplanned routing, causing the model to expose unnecessary intermediate reasoning structures, override more appropriate skills, or produce verbose traceability outputs where they are not safe or needed.

Missing User Warnings

High
Confidence
95% confidence
Finding
The method explicitly recommends 'clear and bulk rewrite' as a performance optimization, but does not require confirmation, backup, transactional safeguards, or a warning about overwrite/data-loss risk. In the context of a data-analysis skill that may generate automation templates and sync workflows, this can directly lead to destructive writes against user datasets or connected systems if applied blindly.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document recommends storing hashes, data, and timestamps in a local cache file without addressing retention limits, file permissions, encryption, or the possibility that synchronized content may include sensitive records. Because this skill is oriented toward data analysis and repeated processing, local persistence can unintentionally expose personal, proprietary, or regulated data through disk storage, backups, or shared workstations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases for this method include very generic requests such as asking to 'draw a chart', 'visualization', 'beautify', or 'add interactive effects', which can cause the skill to activate in many ordinary conversations outside its intended scope. Over-broad activation is dangerous because it can hijack routing, steer users into this skill when a narrower or safer skill should respond, and increase the chance of generating code or workflow guidance in contexts where the user did not explicitly request this methodology.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and overlap with common data-analysis language such as '多维关系' and '交叉分析可视化', which can cause the skill to activate outside its intended scope. While this is not a code-execution issue, unintended activation can steer users into this skill's workflow when another skill or a neutral response would be more appropriate, increasing the chance of misleading outputs or unnecessary file/template generation behavior in the broader skill context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger examples include very broad phrases such as '写 SQL', '生成代码', and '让 AI 帮我写', which are common across many unrelated conversations. In a skill-routing system, this can cause unintended invocation of this skill, leading the agent to generate SQL/code or follow this methodology when the user did not intend to enter this workflow.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document explicitly recommends persisting intermediate analysis artifacts to disk as CSV, JSON, SQLite, and prompt directories, but gives no warning about sensitive data handling, retention limits, access controls, or user consent. In the context of resume analysis and data-analysis workflows, this can cause unintentional local storage of personal, confidential, or regulated data that outlives the session and may be exposed to other users or processes.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The recommendation to use incremental synchronization with an ai_cache.json fingerprint cache introduces retained state across runs without discussing what data the cache contains, how long it is kept, or whether it may encode sensitive business or personal information. Persistent caches can silently accumulate sensitive metadata and create replay, leakage, or cross-task contamination risks, especially in recurring analysis jobs.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The router explicitly instructs the agent to create and update multiple repository files during L0.4, but it does not require a clear user-facing confirmation before making persistent changes. In an agent setting, this creates a real risk of unauthorized or unexpected modification of project artifacts, especially when processing untrusted tutorial inputs that can influence what gets written into methods, routing, index, and test files.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly encourages users to upload sample resumes, contracts, invoices, reports, and table excerpts for analysis, but provides no data minimization, redaction, consent, or retention guidance. Because these materials commonly contain PII, financial data, or confidential business information, the workflow increases the likelihood of unnecessary sensitive data disclosure to the assistant or downstream tooling.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill offers to generate a Windows .bat one-click execution template tied to automation, logging, failure handling, and verification, but gives no warning that generated scripts can execute commands on the user's machine and may alter files, process data, or create persistence through scheduled use. Users may treat the generated batch file as safe by default and run it without manual review, creating avoidable local execution risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases for M12–M16 are broad natural-language fragments such as '画个图', '可视化', and '为什么这个结论', which are likely to appear in ordinary user requests and can cause unintended routing into higher-autonomy or more complex behaviors. In a skill that can generate analysis logic, visualization code, automation templates, and self-expanding workflows, ambiguous activation increases the risk of the agent taking actions or producing outputs outside the user's intended scope.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The exploratory-analysis section explicitly instructs the AI to maximize autonomy, avoid requiring concrete metrics or plotting instructions, and proactively drill down based on what it finds. That ambiguity can lead to scope expansion, speculative analysis, or unsolicited transformations, especially in a skill designed to produce derived analysis prompts, code, and methodological routing rather than just answer narrowly constrained questions.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger keywords are broad enough that ordinary user phrasing could incorrectly route a request into data collection, extraction, or reporting flows the user did not intend. In an agent skill, overbroad routing can cause the system to gather unnecessary data, generate unsafe guidance, or invoke the wrong workflow with sensitive inputs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.