ACT

Security checks across malware telemetry and agentic risk

Overview

This ACT prep skill is a documentation-only assistant that stores study progress locally, with no evidence of hidden code, network access, or credential use.

Safe to install for ACT preparation. Treat ~/act/ as private because it may contain scores, target colleges, practice history, and possibly multi-student notes; review or delete that folder when the data is no longer needed, especially on shared devices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill specifies persistent storage of user academic data under ~/act/ without clearly informing the user that personal study profiles, target colleges, and performance history may be written to local disk. This can expose sensitive educational and planning data to other local users, backups, or unintended retention, especially on shared or managed devices.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal