高校学位论文智能评审 v2.0

Security checks across malware telemetry and agentic risk

Overview

This is a coherent thesis-review skill, but users should treat thesis content and generated review files as confidential.

Install only if you are allowed to process thesis PDFs in this environment. Before using it, confirm which files will be read, avoid web searches with identifying or novel unpublished research details unless authorized, and store generated Word review files in an access-controlled location.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is broad and overlaps with ordinary academic phrases such as '论文评审' and '评审意见', making accidental activation plausible during normal user conversation. In this skill, unintended invocation could cause the agent to begin processing thesis PDFs, performing analysis steps, or initiating downstream actions the user did not explicitly request.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to use external web search and generate .docx files, but it does not clearly disclose these side effects or require user confirmation before network access or filesystem writes. This creates a real risk of unexpected data egress from thesis content or silent creation of local artifacts, which is especially sensitive in blind review, unpublished research, or confidential academic workflows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal