Back to skill

Security audit

🎧 个性化英语听力训练师

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent English listening tutor, but it asks to broadly activate and can read or update learner profiles while also promising automatic reminders and monthly reports without clear opt-in and cancellation controls.

Review before installing. The skill appears educational rather than malicious, but it should ideally require explicit consent before reading or updating learner DNA, saving listening history, scheduling reminders, or generating monthly reports. For child learners, confirm who controls the profile data, how reminders are enabled or cancelled, and how stored vocabulary or progress history can be viewed and deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill says cross-session memory should only be used with consent or when the platform supports it, but later behavior promises storing new words and generating follow-up reports/reminders automatically. That creates a policy/behavior mismatch that can lead to retention of learner data without clear, current consent, especially since the data concerns minors' learning profiles and activity history.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The promise of sending a flashcard test 24 hours later introduces proactive reminder/scheduling behavior beyond immediate listening-practice assistance. If implemented without explicit opt-in, it can create unsolicited re-contact, background tasking, and additional storage of study history that users may not expect from a listening-material skill.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
Automatic monthly progress reports expand the skill from generating listening materials into ongoing surveillance and longitudinal profiling of the user's behavior. In an education context—potentially involving children—this increases privacy risk because it requires retaining practice frequency, topics, and performance data over time.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The instruction to invoke this skill for essentially any English listening-related scenario is overly broad and can cause unintended activation in cases where the user did not request personalized generation or data-linked coaching. Overbroad activation matters here because the skill also interacts with other memory/profile systems, increasing the chance of unnecessary data access or collection.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Several trigger phrases are common conversational statements like wanting to practice listening or saying listening is hard, which may match ordinary discussion rather than a request to activate a skill. This can lead to accidental invocation and, in context, unnecessary retrieval of learning-profile data or initiation of coaching flows the user did not intend.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.