Back to skill

Security audit

深圳中考填报助手

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Shenzhen school-admissions helper with a disclosed but promotional WeChat consulting callout.

Use the policy and school-planning content as public-data guidance only, verify important admissions details with official Shenzhen education sources, and avoid sharing a child's personal records or contact details through the listed WeChat unless you independently trust that consultant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill embeds an off-platform call to contact a specific WeChat account for 'one-to-one precise plans,' which turns a public educational assistant into a lead-generation funnel. This is risky because it directs users away from the platform's oversight, safety controls, and logging, increasing the chance of unreviewed solicitation, privacy exposure, or social engineering of parents/students.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The dedicated '深度服务' section explicitly advertises a named consultant and personal WeChat for customized consulting, which is outside the assistant's stated informational purpose. In this context—serving minors and parents making school decisions—off-platform solicitation is more concerning because it can pressure vulnerable users into private interactions without platform moderation or clear privacy safeguards.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.