Back to skill

Security audit

✍️ 英语写作进化教练

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed English writing-coach skill with consent-gated progress tracking and no executable install or hidden behavior.

Before installing, understand that this skill is designed to remember writing-development patterns when you allow tracking. Use it for English writing feedback, and decline DNA/profile updates or reminders if you do not want progress information stored across sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises activation on broad phrases like 'help me correct/check my English' and 'how can I improve my English writing,' which can match many general-language-assistance requests. This creates overbroad routing risk: the system may invoke this skill in contexts where the user did not specifically ask for writing coaching, causing unintended data handling, confusing behavior, or bypass of more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The instruction that the skill 'must be invoked' for any scenario involving English writing practice or expression improvement is overly absolute and ambiguous. In a multi-skill agent, mandatory broad activation can crowd out contextual selection, causing unnecessary invocation, privacy exposure for submitted text, and reduced user control over whether longitudinal tracking or coaching-style interaction is appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.