SAT

Security checks across malware telemetry and agentic risk

Overview

This SAT prep skill is purpose-aligned and instruction-only, with the main privacy consideration that it saves study progress locally under ~/sat/.

Install if you are comfortable with the agent creating and updating local SAT study notes in ~/sat/. Avoid storing unnecessary personal details there, and review or delete that folder when you no longer want your scores, mistakes, target colleges, or study feedback retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs that detailed SAT-related user data be persisted under ~/sat/, including profile information, test dates, scores, mistakes, and study feedback, but provides no notice, consent flow, retention policy, or privacy safeguards. While this is not obviously malicious, it creates a real privacy risk because educational performance data and planning details are stored locally in a predictable location where other local users, backups, or tooling could access them unintentionally.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill instructs persistent writes to files under `~/sat/` to maintain study records, but it does not warn the user that local files will be created and updated over time. While the content being stored is low-sensitivity educational data, silent persistence can still surprise users, overwrite existing notes, or create unintended local data retention.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal