Back to skill

Security audit

❌ 智能错题本

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed educational wrong-answer analysis skill that records study errors and coordinates with related learning skills, with no evidence of hidden or destructive behavior.

Before installing, consider that the skill is designed to save and reuse student wrong-answer history, weak-point labels, reports, reminders, and some anxiety-related learning context across related skills. Use it where that learning-data retention and cross-skill sharing are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
技能描述写明当学生说“我这道题做错了”“帮我分析错误原因”时建议激活,其中“帮我分析错误原因”过于宽泛,缺少明确限定必须与题目、作业或错题场景绑定。该类表达可出现在一般聊天、情绪表达或非学科任务中,容易与日常话语冲突。

Vague Triggers

Medium
Confidence
90% confidence
Finding
“帮我看看哪里错了”“为什么我总在这种题上出错”可用于多种非本技能专属场景,而文档未说明是否仅在已提供题目、答案、过程或错题上下文时触发。缺少负例或上下文约束会让调用边界不清晰。

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.