Back to skill

Security audit

🔭 跨学科侦探周

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese educational study-planning skill with disclosed note-taking and knowledge-connection behavior, and no executable or hidden high-impact actions.

Install this if you want a Chinese-language learning assistant workflow for cross-disciplinary projects. Be aware that it is designed to connect with other learning-note skills and may read or update study records such as Cornell notes and a knowledge accumulation tree.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The description recommends activating this skill for broad phrases such as "帮我联系不同学科的知识", "我想做一个主题研究", and "帮我做项目学习", then further expands scope to "凡是涉及跨学科联结、主题研究、知识网络构建的场景,务必调用此SKILL". These triggers are ambiguous and expansive enough to match many ordinary educational conversations, increasing the risk of unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The manifest and examples consistently prescribe Chinese-language invocation phrases and interaction patterns, but do not offer the user any language or locale option. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern unless the regional limitation is explicitly justified.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.