USMLE

Security checks across malware telemetry and agentic risk

Overview

This USMLE study skill is a disclosed local study tracker with no evidence of hidden execution, credential access, network transfer, or destructive behavior.

Safe to install for ordinary use. Before using it, decide what exam dates, scores, residency goals, wrong-answer notes, and wellbeing information you are comfortable saving locally, and review or delete the ~/usmle/ folder if privacy matters on your device.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This markdown file describes storing profile, progress, assessments, and feedback under a fixed local directory, which affects user data on disk. The section explains where data lives but does not clearly warn the user that the skill will create and maintain persistent records on their system or advise them to avoid storing sensitive personal information there.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal