Back to skill

Security audit

🎙️ 英语口语陪练

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate English speaking coach, but it uses broad activation rules and persistent learner profiling that users should review before installing.

Install only if you are comfortable with a speaking coach that may remember pronunciation weaknesses, fluency patterns, vocabulary, milestones, and topic preferences across sessions. Prefer using it with explicit coaching requests, and avoid enabling continuous tracking or reminders unless the platform gives clear controls to view, limit, and delete the stored profile.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill says that whenever the interaction involves English speaking, oral practice, or pronunciation training, the system should invoke this skill. That trigger scope is extremely broad and can hijack many normal conversations, causing unintended activation and unnecessary access to memory-linked features. Because this skill also ties into persistent user profiling, over-activation increases privacy and consent risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Triggering on a student opening voice mode or saying common greetings like 'Good morning' is too ambiguous. These behaviors are routine and not strong evidence that the user wants this specific coaching workflow, which can lead to accidental activation and unnecessary collection or use of profile data.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The listed trigger phrases include very common requests like '练口语' and '帮我练英语对话', which are broad enough to collide with ordinary educational chat. While appropriate for discoverability, using them as unconditional activation criteria can route users into this skill when they may have wanted a simpler answer or a different tool.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger state activates on very broad conditions such as entering voice mode, saying "Good morning," or generic practice-start phrases, which can cause the skill to launch without clear user intent. In a voice-driven skill that persists conversational data and stores "DNA"-like learner profiles, accidental activation increases privacy risk and can steer unrelated conversations into the skill workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The opener logic for returning users says to read prior "口语DNA" and continue from stored weaknesses, but the invocation examples remain vague and insufficiently bounded. This combination makes accidental invocation more dangerous because a casual phrase could trigger retrieval and use of previously stored learner data without a strong, current consent signal.

Ssd 3

Medium
Confidence
96% confidence
Finding
The description explicitly states that, when continuous tracking is allowed, the skill remembers pronunciation weaknesses across sessions. Cross-session retention of user speech-derived data creates privacy risk, especially if consent is unclear, retention is indefinite, or the data is reused in contexts the user did not expect.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill describes a long-term 'oral DNA' memory backed by persistent local storage, not transient model context. Persistently recording pronunciation weaknesses and reusing them later can reveal sensitive behavioral patterns about a learner and increases the blast radius of any memory misuse or unauthorized access.

Ssd 3

Medium
Confidence
92% confidence
Finding
Although the text says memory use should occur only when the user allows it, the skill still instructs the assistant to record and continue profile data across sessions. Natural-language memory policies are easy to apply inconsistently, so without enforceable consent checks and minimization, this becomes a genuine data retention vulnerability rather than merely a design note.

Ssd 3

Medium
Confidence
88% confidence
Finding
Storing conversation-derived expressions into a user 'DNA' profile extends retention beyond the immediate lesson and can build a detailed behavioral record over time. Even though the flow asks the user to say '存' to record an item, the consent is narrow and may not fully communicate retention scope, sharing, or future reuse.

Ssd 3

Medium
Confidence
97% confidence
Finding
The defined internal profile aggregates pronunciation weaknesses, pause patterns, conversation duration, vocabulary usage, milestones, and topic preferences. This is a fairly rich longitudinal learner profile, and if exposed, overused, or shared across skills without strict controls, it can leak sensitive personal traits and behavior patterns well beyond what is necessary for a single tutoring session.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.