Back to skill

Security audit

文言文复活计划

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Chinese classical literature tutoring skill with broad activation wording but no executable code, hidden data access, or unsafe authority.

Installers should expect this skill to activate broadly for classical Chinese, ancient poetry, memorization, and related writing-help requests. Review the companion-skill integrations if you do not want study progress, quotation material, or review reminders recorded by other skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The instruction '凡是涉及古诗文、文言文理解、诗词背诵的场景,务必调用此SKILL' is overly broad and can force activation for a wide range of ordinary tutoring requests, even when a narrower or more appropriate skill would suffice. This increases the chance of misrouting, unnecessary roleplay behavior, and unintended interference with normal educational workflows.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The listed trigger phrases are broad, natural tutoring requests that overlap with common classroom help, so the skill may activate in situations that do not actually require this specialized behavior. In practice, this can crowd out safer or more context-appropriate responses and create reliability issues through over-invocation rather than direct code execution risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.