Back to skill

Security audit

康奈尔笔记

Security checks across malware telemetry and agentic risk

Overview

This skill coherently helps organize and retrieve student Cornell notes, with disclosed memory use and no executable code or hidden install behavior.

Before installing, be aware that this skill is designed to remember and reuse uploaded class notes, generated summaries, keywords, links to other notes, and retrieval history. Use it when you are comfortable with that study-memory behavior, and rely on platform controls to disable or delete saved note data if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill repeatedly instructs the host to invoke it for very broad study scenarios, including essentially any note-organizing, extraction, or review-prep request. That can cause over-triggering and unnecessary activation of note ingestion, storage, and cross-skill linking features, increasing the chance of collecting or surfacing student data when the user did not explicitly request this specific workflow.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The metadata and behavior describe cross-session storage of uploaded notes, generated summaries, keywords, and retrieval history, but the user-facing description does not clearly warn that this data may persist and be reused later. In an education context involving student notes, this omission can undermine informed consent and lead to unexpected retention or resurfacing of potentially sensitive academic information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.