Back to skill

Security audit

笔记手账

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a prompt-template guide, but some youth-facing anime style options are under-scoped and could steer educational outputs toward age-ambiguous or fetish-adjacent character imagery.

Install only if you are comfortable with the anime and pink style presets, and prefer using the default notebook or other non-character styles for youth education. Review or remove the character/costume triggers and style elements if this will be used around children or in a classroom setting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is described as an educational note-card prompt generator, but this section expands it into anime/girl-themed character, costume, and accessory prompting unrelated to note formatting. Because the skill is also positioned for youth-oriented educational use, these additions create unnecessary characterization and appearance-generation behaviors that can steer outputs toward inappropriate or sexualized minors-adjacent content.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
This section includes youth-facing prompts for 'Q版萌系角色', cat/animal-ear girls, maid outfits, over-knee socks, lace, blushing, and other appearance-focused elements that are not justified by the educational function of the skill. In a skill aimed at low-grade students and '萌系爱好者', these elements materially increase the risk of generating fetish-adjacent or sexualized depictions of young-looking characters, making the context significantly more dangerous.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains broad, generic terms such as style/theme keywords that may match ordinary user requests outside the intended scope, causing unintended activation of the skill. In an agent setting, overbroad activation can route benign conversations into file-writing or prompt-generation behavior unexpectedly, increasing the chance of incorrect tool use or user confusion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.