Back to skill

Security audit

Study Tutor

Security checks for vulnerabilities and agentic risk

Overview

This is a tutoring skill with disclosed, narrow file and network rules; its main consideration is optional persistent study notes for long-term learning.

Before installing, be aware that the skill may create or update a learning profile under memory/{subject}-study.md to track goals, progress, weak points, mistakes, and review dates. Avoid putting sensitive personal details in study materials or profiles, and review or delete the profile if you do not want study history retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes maintaining a persistent study profile in memory/{subject}-study.md across sessions, but it does not mention obtaining user consent, retention expectations, or what data will be stored. In a learning context, these records may contain sensitive educational data, weaknesses, schedules, and possibly personal details, so silent persistence creates a meaningful privacy and transparency risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples are broad, everyday study-related phrases such as asking for help with homework or review, which can cause the skill to activate in many loosely related contexts. This increases the chance of unintended routing or invocation, especially if activation relies on keyword-style matching rather than explicit user consent, though the file does not suggest malicious abuse by the author.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly describes persistent learning-profile storage in memory/{subject}-study.md without warning the user that notes may be retained across sessions or that files may be created. This can lead to unconsented retention of potentially sensitive educational data, including weaknesses, mistakes, goals, and study history, creating privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says to use the skill when users say things like 'I don’t understand this concept,' 'Help me solve this homework problem,' and 'Make me a study plan.' These are broad, everyday requests with no exclusion conditions or scope boundaries, so they could match many unrelated assistant interactions and cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file structure and accompanying note state that 'SKILL.md' is 'English only' and that the Chinese skill file was intentionally removed because the skill itself is required to be English only. This is a natural-language policy issue because it forces a language constraint without user opt-in or a documented necessity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.