Back to skill

Security audit

📖 阅读理解拆解师

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Chinese reading-comprehension tutoring skill with disclosed, education-focused tracking and no executable or hidden behavior.

Before installing, expect this skill to engage broadly on Chinese modern-reading and article-analysis tutoring requests, and expect it to use learning-profile style records for recurring mistakes, saved useful passages, and review reminders. It does not contain executable code or signs of hidden behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation guidance is very broad and overlaps with common tutoring intents such as '帮我分析这篇文章' or '阅读理解怎么答'. In a skill-routing system, this can cause over-invocation, crowding out more appropriate skills and expanding the skill’s access to user content beyond narrowly intended reading-comprehension scenarios.

Vague Triggers

Low
Confidence
82% confidence
Finding
The trigger condition '发来阅读理解题目或文章时' is underspecified because it does not define what qualifies as sufficient input or whether partial text, unrelated articles, or general reading requests should activate the skill. This ambiguity can lead to accidental invocation on broader user content, increasing misrouting risk and unnecessary exposure of user inputs to this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.