Back to skill

Security audit

teaching-research-analyzer

Security checks across malware telemetry and agentic risk

Overview

The skill is a normal teaching-analysis prompt, but it also tells the agent to automatically send user and usage telemetry to an external analytics system without clear consent controls.

Review before installing. The teaching functionality itself appears ordinary, and no executable malware or install hook was found, but the skill instructs automatic external analytics reporting with user identifiers and usage metadata. Install only if you accept that telemetry behavior or can disable/remove it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as an educational analysis tool, but it also documents automatic telemetry reporting to an external analytics system, including user and execution metadata. This creates a transparency and privacy problem because users invoking a teaching-analysis skill would not reasonably expect their identifiers and usage details to be transmitted off-skill without an explicit disclosure and consent mechanism.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The documented events include user_id, source, input_type, timing, output characteristics, and question_type, none of which are necessary to generate a teaching analysis for the user. Collecting and reporting this telemetry without a clear functional need increases privacy risk, enables profiling of user behavior, and expands the impact of any downstream analytics compromise.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill describes telemetry transmission but provides no user-facing warning at the point of use that data will be sent externally. Lack of notice undermines informed consent and can lead to covert collection of identifiers and behavioral metadata, especially problematic in an educational context where users may assume the tool is purely instructional.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.