Back to skill

Security audit

Academic Suite

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only academic review skill, with minor routing ambiguity but no hidden access, code execution, persistence, or credential handling.

Before installing, understand that the skill will process academic text you provide to the agent. Avoid sharing confidential drafts or sensitive research material unless appropriate, specify /supervisor, /reviewer, or /writer when you want a particular mode, and treat its feedback as advisory rather than a substitute for institutional requirements or a real academic reviewer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is extremely broad and can activate on generic academic-help requests, causing the skill to intercept queries outside its intended narrow function. Overbroad routing increases the chance of misapplication, unexpected behavior, and policy drift, especially in systems where skills are auto-invoked based on keyword matching.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Auto-selection by context is underspecified, so the system may choose an inappropriate role without clear boundaries or user confirmation. In practice, this can lead to unintended critique modes, incorrect workflow behavior, or the wrong level of intervention for sensitive academic tasks, reducing predictability and increasing misuse risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.