Back to skill

Security audit

玩转AI校园(BNBU)

Security checks across malware telemetry and agentic risk

Overview

The skill is aligned with AI teaching, but its cloud sharing, device actions, and automatic syncing of learning data need review before installation.

Review this skill before installing in any real class or organization. Use it only if you are comfortable with teaching materials, assessment reports, and learning progress being stored locally and potentially synced or saved to IMA/Tencent Docs. Require explicit confirmation before sharing, saving to cloud, creating reminders/calendar items, or uploading results, and avoid entering student names, contact details, or other sensitive learner data.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases listed in the README are broad, common-language terms like '教学', '游戏', and '练习题', which can cause accidental activation in unrelated conversations. In an agent skill, overly broad triggers increase the chance of unintentional execution of high-capability workflows such as file generation, assessment, collaboration, or data-affecting actions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README advertises offline caching, automatic sync, and collaborative features that affect user data, but it does not warn users about what data is stored locally, what is synchronized, when sync occurs, or who can access shared content. This creates privacy and integrity risk because users may unknowingly persist sensitive educational content or learner data across devices and cloud collaboration flows.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger matrix uses very broad educational phrases like '课件', '备课材料', '教学演示', and similar generic requests that commonly appear in unrelated contexts. This can cause unintended invocation or misrouting of the skill, leading the agent to activate capabilities the user did not explicitly request, especially when combined with cloud/storage and device-side actions elsewhere in the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The WorkBuddy-enhanced triggers such as previewing, saving to knowledge bases, saving to Tencent Docs, or sharing to a teaching group are ambiguous enough to match ordinary collaboration language. If overmatched, the skill may initiate or prepare external persistence/sharing flows without sufficiently clear user intent, increasing the chance of data exposure or surprising side effects.

Vague Triggers

Low
Confidence
83% confidence
Finding
Routing generic terms like '讲义 / 文档' by default to the courseware capability is overly vague and may misclassify user intent. While the direct security impact is lower than storage or device actions, incorrect routing can still trigger unexpected generation paths and create confusion that weakens informed consent for downstream actions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Triggers like '设提醒', '排日历', '记备忘录', and '复制 Prompt' are everyday phrases that can appear casually in normal conversation and are not tightly scoped to this skill. In a WorkBuddy-integrated environment, this makes accidental invocation of device-side capabilities more plausible and could cause unintended reminders, calendar entries, memo creation, or clipboard operations.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises cloud storage, sharing, clipboard, and device-side integrations but does not prominently warn users about privacy and data-handling implications. Users may provide teaching materials, assessments, or student-related content without realizing it could be persisted, synced, shared, or copied into external systems.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The section on native retrieval and cloud persistence describes external storage and retrieval flows without a clear warning that content may be stored in third-party or organizational repositories. In an educational context, this is risky because lesson plans, assessments, and possibly sensitive student-related materials could be persisted beyond the user's expectation.

Vague Triggers

Low
Confidence
91% confidence
Finding
The manifest advertises very broad capabilities across content generation, assessment, recommendation, collaboration, document storage, and device-integrated teaching workflows without clearly defining activation boundaries, prohibited operations, or exclusion conditions. In an agentic environment, this ambiguity can cause the skill to be invoked in contexts beyond its intended educational scope, increasing the chance of overscoped actions, accidental misuse, or unsafe handling of user requests and connected services.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases include broad everyday terms like '测评', '练习题', and '检查我学得怎么样', which can cause the skill to activate unintentionally in unrelated contexts. In an educational assistant that can generate assessments, store progress, and produce reports, accidental invocation could lead to unwanted data collection, workflow hijacking, or confusing behavior for users.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document describes scoring, weakness diagnosis, report generation, and later '上报成绩' without any clear notice, consent flow, retention policy, or explanation of what learner data is processed. Because this is an assessment system handling educational performance data, the lack of user transparency increases privacy and compliance risk, especially for minors or institutional deployments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrase list includes the broad everyday term "协作" by itself, which can cause unintended activation in many benign conversations unrelated to collaborative lesson planning. In an agent skill context, over-broad triggers increase the chance of the wrong capability being invoked, which can lead to confusing behavior, unauthorized workflow transitions, or accidental access to collaboration-related features.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases such as “协作”, “批注”, and “讨论” are very broad and commonly appear in ordinary user requests, making the skill likely to activate outside its intended scope. In an agent environment, overbroad activation can cause unintended invocation of collaboration workflows, document-sharing behavior, or downstream actions in connected platforms like Tencent Docs or WorkBuddy features.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The module defines an automatic trigger on broad terms like “博智坊”, “工作坊”, and “认证计划” without explicit scope checks, which can cause the skill to activate or steer behavior in contexts the user did not intend. In a multi-skill or agentic environment, overly broad routing conditions can lead to prompt hijacking of unrelated requests, incorrect tool selection, or unauthorized context switching.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The guide explicitly promotes persistent local storage of AI-generated content, learning progress, and assessment results, but it does not require a user-facing disclosure, consent flow, retention control, or device-sharing warning. In an education context, these records can reveal study behavior and performance data to other users of the same device or be retained longer than expected, creating a real privacy and transparency risk even if data does not initially leave the device.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The design states that when the network returns, the system automatically syncs local data and may upload assessment results, but it does not require a prominent warning or user approval before transmission. This is dangerous because users may reasonably believe 'offline/private on device' data remains local, while reconnecting can silently send performance data to the server, undermining privacy expectations and consent.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The prompt hard-codes Chinese as the default response language and only allows switching when the user explicitly requests another language. This creates an unnecessary language/region restriction that can impair usability, accessibility, and policy compliance in multilingual environments, especially when the surrounding platform or user context implies another language should be used.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes very broad, common phrases such as '课程规划', '学习建议', and '从哪里开始', which can overlap with ordinary conversation and cause the skill to activate unexpectedly. In an agent environment, overbroad activation can route unrelated user requests into this skill, increasing the chance of unintended behavior, confusion, or inappropriate access to connected capabilities.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases include broad natural-language commands such as saving to a knowledge base, sharing, setting reminders, or writing notes, but the document does not define strict confirmation, scoping, or disambiguation requirements before invoking those actions. In an agent environment with device-side and cloud-integrated capabilities, this can cause unintended writes, sharing, or scheduling from ambiguous user messages, increasing the risk of privacy leakage or unauthorized side effects.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.