Back to skill

Security audit

ai-literacy-expert-v3

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AI-literacy and p5.js courseware skill with no install-time execution, though users should notice that it tends to generate full HTML courseware by default.

Install this if you want an AI literacy teaching assistant that often produces complete interactive p5.js HTML courseware. Before using generated HTML with students, review external CDN use and any browser permissions. Treat the Hooks material as conceptual education: only copy hook configurations you understand, in trusted projects, and after checking the commands they run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill auto-triggers full p5.js courseware generation on very broad education-related phrases such as '课件', '备课材料', and even ambiguous '讲义' unless the user explicitly opts out. This can override likely user intent, causing the agent to produce large code artifacts unexpectedly, increasing prompt-scope creep, token/cost usage, and the chance of unsafe or unreviewed code being delivered in contexts where a simple explanation was expected.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document explicitly instructs users on configuring Hooks that execute arbitrary shell commands with the user's privileges, including examples around intercepting dangerous commands. Although it does include some later cautionary text, the content still operationalizes a high-risk mechanism in an educational skill, which can normalize or enable unsafe command execution if copied without strong guardrails, review steps, sandboxing, and least-privilege guidance.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.