Back to skill

Security audit

Art Of Questioning

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only questioning coach; its broad auto-activation and optional scheduled practice are worth noticing, but it shows no code execution, credential use, file access, or data export.

Install if you want a Chinese-language coach for deeper questioning and critical-thinking practice. Be aware it may activate on broad questioning or learning-related phrases, and avoid enabling scheduled practice unless you want recurring exercises.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad natural-language phrases such as '如何提问', '帮我提问', and '深度思考', which can match many ordinary conversations unrelated to this skill’s intended scope. Over-broad triggers increase the chance of unintended invocation, causing context switching, unexpected behavior, or accidental processing of user content under the wrong skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction '用户描述内容即自动进入实战模式' makes activation dependent on a very broad condition: virtually any user description of something they are reading, hearing, or learning. This weak boundary can cause the skill to engage without clear consent, increasing the risk of misrouting user requests and applying the skill in contexts where it was not intended.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.