Back to skill

Security audit

⏰ IM智能提醒

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed study reminder skill, but one reference allows reminders to continue weekly after repeated silence, which needs review before installation.

Review this skill before installing, especially for student or guardian use. It should be changed so repeated non-response pauses reminders or requires renewed confirmation, and every reminder series should clearly expose pause/cancel controls. The learning-profile timing feature appears disclosed, but should only be enabled with explicit sharing consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The document explicitly says that after three unanswered reminders, the system should 'reduce frequency but not stop' and continue weekly until the student resumes use. That conflicts with the skill metadata stating no idle wake-up messages without authorization, and creates a persistence behavior that can override user disengagement as an implicit signal to stop. In a reminder system for students, this is risky because non-response may indicate revoked consent, changed circumstances, or a need for quiet hours rather than permission to keep messaging indefinitely.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
The reference recommends selecting reminder times based on a 'learning DNA' profile and categorizing students into behavioral types. Even if intended for optimization, this broadens data collection and inference beyond the core purpose of sending requested reminders, increasing privacy and profiling risk—especially for minors. The skill context makes this more sensitive because educational reminders should minimize personal-data processing unless clearly necessary and consented to.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The closing marketing-style promise says the assistant will appear when the user is most forgetful, procrastinating, or interrupted, which implies behavioral targeting or proactive intervention beyond the explicit consent boundaries described elsewhere in the skill. Even though the rest of the skill repeatedly requires authorization, this language can encourage implementations that infer vulnerable moments from activity patterns and trigger reminders without sufficiently specific opt-in.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown specifies persistent reminders after repeated non-response but does not mention any warning, pause flow, or opt-out disclosure. This undermines informed consent and can trap users in continued messaging they may no longer want, particularly problematic for students and guardians who may interpret silence as sufficient disengagement. In this skill's context, the absence of an explicit stop/pause disclosure makes the persistence behavior more dangerous, not less.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.