Back to skill

Security audit

shiny-teaching-dashboard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed R Shiny teaching-dashboard helper with normal local file-generation and package-install guidance, not hidden or destructive behavior.

Install this if you want help building R Shiny classroom dashboards. Be aware it may steer broad interactive-lesson requests toward Shiny and may default to Chinese phrasing unless you specify another language or stack.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are extremely broad and include generic requests like making course content interactive or replacing PPTs, which can cause the skill to activate in situations where the user did not specifically ask for R/Shiny. Over-broad routing can misdirect the agent, override more appropriate tools, and increase the chance of unwanted file-writing behavior or irrelevant framework assumptions.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill imposes Chinese-language and formatting conventions in its output contract, including punctuation and response-style constraints, without checking user language preference. This can cause instruction conflict, reduce reliability, and make the agent ignore the user's requested locale or communication style, which is a policy and routing risk even if not a direct code-execution issue.

Static analysis

No suspicious patterns detected.