Back to skill

Security audit

fore-vip-kids-science

Security checks across malware telemetry and agentic risk

Overview

This skill coherently creates child-friendly science answers with illustrations and a local HTML page, with optional user-directed sharing.

Use the skill for illustrated children's science explanations, but choose local-only if the prompt or generated page includes a child's name, school, location, health details, or other personal information. Before selecting 资料库, IMA, or 腾讯文档, confirm you are comfortable publishing the final HTML page to that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The guide extends the skill from generating a local HTML artifact to optionally uploading it to internal and third-party repositories and document platforms. That broadens data egress and account-scope significantly beyond the core educational rendering function, creating risk of unintended disclosure if users are not given clear, informed consent before transmission.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The document grants the skill capability to upload generated content to IMA knowledge bases and Tencent Docs without strong justification tied to the children's science Q&A purpose. Even if the content is innocuous, adding outbound publishing paths increases the blast radius for accidental leakage of prompts, generated content, or user-provided context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill proactively recommends uploading generated illustrated HTML pages about a child’s questions to a repository or external sharing service, but it does not require a privacy warning, consent check, or minimization of child-related personal data before upload. Even if the content seems harmless, questions, age cues, and generated pages can reveal information about a minor’s interests or identity context, creating unnecessary privacy exposure when shared by default.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The sharing guide discusses uploading content to remote services but does not prominently warn that the generated page may be transmitted to external platforms requiring separate connectors or accounts. Users may reasonably assume the skill only creates a local illustrated page, so insufficient disclosure can lead to uninformed data sharing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.