Anki Card Generator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Anki flashcard formatting skill with no code execution, credentials, persistence, or hidden data access.

Safe to install for generating flashcards. Be aware it may activate on broad study-related wording, so phrase requests clearly when you do or do not want Anki-formatted cards; avoid pasting private material unless you want it converted into study cards.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is broad enough to match common phrases like 'flashcards', 'study cards', or 'memorize this' in many benign contexts, which can cause unintended skill activation. In an agent system, over-broad invocation can route user input to the wrong capability, leading to confusing behavior, unwanted formatting transformations, or accidental processing of content the user did not intend to convert into Anki cards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal