Back to skill

Security audit

成都初升高专家

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chengdu school admissions guidance skill with one policy-content inconsistency to verify, but no hidden execution, credential use, or unsafe agent behavior.

Before relying on this skill for enrollment or housing decisions, verify current Chengdu education policies, district maps, and cutoff scores with official sources. Avoid sharing unnecessary personal identifiers, and only allow de-identified workspace notes if that fits your privacy expectations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The document presents an internally inconsistent claim: it correctly states earlier that oversubscribed private junior high admissions must be lottery-only with no written selection, but the FAQ then says Olympiad math can still be a bonus factor. In an education-planning skill, this can mislead families into believing prohibited academic credentials still influence admission, causing misguided preparation, financial loss, or distorted application decisions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.