Back to skill

Security audit

Defense Rehearsal

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed academic-defense rehearsal helper, but users should be aware it can use meeting recordings/transcripts and has default-on local usage tagging.

Install only if you are comfortable with local method-level usage tags being collected by default, and say "别记了" to disable that feature if you do not want it. For rehearsal recordings, get participant consent and avoid uploading unpublished or sensitive research content to Tencent Meeting unless that is acceptable for your situation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The skill claims automatic local-only logging of 'method-level tags' but provides no concrete implementation details, retention limits, or technical guarantees that the data never leaves the device. In a skill that also integrates with external systems such as Tencent Meeting and a literature gateway, this creates a misleading privacy boundary and increases the risk that users consent to telemetry under false assumptions.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill enables always-on post-use telemetry by default ('安装后默认开启') even though continuous usage logging is not necessary to perform defense rehearsal. Default-on telemetry in a high-stakes academic setting can capture sensitive behavioral metadata about preparation habits and meeting usage without sufficiently justified need.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation says data recording starts automatically after installation, but the warning is framed as a feature note rather than a clear privacy notice explaining ongoing collection implications. Users may not understand that repeated use creates a persistent behavioral log, even if the content is described as limited.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to record mock defenses and use transcripts/intelligent meeting summaries for analysis, but it does not provide a strong upfront warning about recording sensitivity, participant consent, transcript handling, or the privacy impact of uploading spoken academic content to a meeting platform. Defense rehearsals can contain unpublished research, student identities, and advisor/committee discussion, making transcript generation especially sensitive.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.