Back to skill

Security audit

English Tutor

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed English tutoring skill, but its package is malformed and may not install or run correctly.

Install only if you specifically want an American English tutor, and expect the publisher to fix the invalid manifest and broken index.js before the skill will run reliably. The stored onboarding preferences are ordinary for this purpose, but users who do not want learning preferences saved should avoid enabling it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description specifies a personalized 'American English tutor,' which imposes a specific language variant as the skill's behavior. Under the policy, locale or language constraints should be optional or clearly justified; this file does not offer a choice or explain why American English is required.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file contains two competing module export styles, with the first module.exports = { async onCommand... block appearing unterminated before a second export default block begins. This can change or break the actual entrypoint the host loads, causing the documented onboarding logic to differ from runtime behavior and creating a supply-chain integrity issue where reviewers may assess one code path while another executes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The onboarding text explicitly brands the skill as an "American English Tutor," which imposes a specific language variety. Elsewhere the file provides no opt-in, alternative locale choice, or justification for restricting the user to American English, matching the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language metadata labels the skill as an "American English Tutor" and describes it as an "American English training system," which imposes a specific language/locale variant by default. The file does not offer a user choice of English variant or explain why American English is required, which conflicts with the locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.