Back to skill

Security audit

Learning Path Navigator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a straightforward learning-plan skill with minor routing and language caveats, not harmful behavior.

Reasonable to install if you want a Chinese/bilingual study-planning helper. Expect generic, simulated resource recommendations rather than live education-platform results, and be aware it may activate on broad learning-plan or learning-resource requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic requests such as learning-plan and resource-recommendation prompts that can easily overlap with normal educational conversations. This can cause the skill to activate unintentionally, hijack unrelated user requests, or override more appropriate skills, increasing prompt-routing risk and reducing user control.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill description and instructions are effectively Chinese-only and do not offer a language-selection mechanism. In multilingual environments this can lead to incorrect routing, user confusion, or mishandling of requests if the agent responds in an unexpected language, though it is primarily a reliability and UX security issue rather than a direct exploit path.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.