Back to skill

Security audit

Gaokao Volunteer Advisor

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed college-admissions advising assistant whose web research and HTML report generation fit its purpose, with a caution to verify unconfirmed safety claims.

This skill is reasonable to install for admissions research, but users should treat school-safety rumors and student-platform posts as leads, not facts. Verify admissions rules, plans, scores, fees, and final submission steps with the provincial exam authority and school websites, and do not provide ID numbers, exam credentials, passwords, or verification codes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The playbook instructs the agent to label unverified safety-related information as 'worth vigilance' even when it is not confirmed. In a college-advising context, this can amplify rumors or defamatory claims and may cause users to make high-stakes education decisions based on unreliable allegations, especially because the skill explicitly emphasizes investigating school safety and negative incidents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.