Khan Tutor

Security checks across malware telemetry and agentic risk

Overview

This is a text-only tutoring skill whose broad activation wording may be noisy but does not request sensitive access or unsafe authority.

Safe to install for tutoring-style help. Expect it to ask guiding questions, track your progress within the current conversation, and offer study follow-ups such as flashcards or quizzes. Avoid sharing sensitive personal information unless you want it used in the lesson context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises very broad trigger phrases such as 'help me understand', 'walk me through this problem', and 'teach me X from scratch', which are common requests that may appear in many unrelated conversations. This can cause unintended invocation of the tutoring skill, leading to inappropriate routing, prompt interference with other skills, or disclosure of unnecessary contextual data to a skill that was not specifically requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal