Back to skill

Security audit

🧬 学习DNA

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed student learning-memory tool, but it asks agents to maintain persistent profiles, inferred emotional data, and cross-skill sharing with some under-scoped automatic update instructions.

Review before installing. Use this only where a student or guardian has explicitly opted into long-term learning memory, and keep emotion tracking, reminders, and cross-skill sharing off unless separately needed. Confirm the platform enforces view, correct, delete, pause-memory, and pause-sharing controls, and avoid treating inferred emotion fields as clinical or authoritative assessments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The template authorizes automatic long-term profile updates from ordinary study phrases like '我懂了' or '我考试考了XX分', which exceeds the stated consent-gated activation model in the skill metadata. In an education context involving minors, this creates a real risk of persistent data collection and behavioral profiling without a fresh, explicit opt-in at the moment of capture.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The milestone '能在未被提醒的情况下主动关联历史记录' encourages proactive use of stored history even when the user did not request memory use in that interaction. That conflicts with the declared behavior that normal Q&A should not force memory use, and increases the chance of covert cross-session personalization.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The template instructs the skill to trigger external reminder and error-book skills based on conversational cues, expanding behavior beyond simple memory maintenance. This creates unauthorized function chaining and potential data sharing to other components without clear user awareness or purpose limitation.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The document instructs the agent to proactively notify students and record milestones into persistent '学习DNA' memory whenever conditions are met, without reiterating the manifest's requirement that cross-session memory only be used after explicit opt-in. In a student context, this can lead to unauthorized profiling and retention of behavioral and performance data across sessions, conflicting with the stated consent boundary.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The monthly review and '主动调取' instructions direct the agent to retrieve stored milestones during summaries or when asked about progress, which operationalizes persistent memory use as part of normal tutoring flows. Because the skill metadata says ordinary Q&A should not force memory use and cross-session profiles require explicit consent, these instructions risk bypassing consent and exposing previously stored student data.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The schema introduces `reminderConsent`, which implies a reminder/messaging capability beyond the stated long-term memory engine scope. Scope expansion in a data schema is dangerous because downstream systems may begin collecting consent for, or later enabling, outbound reminders without the same visibility, review, or least-privilege controls described in the skill metadata.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The `learningEmotion` section stores inferred emotional and motivational profiling, including anxiety triggers, avoidance patterns, and mood baselines derived from AI inference rather than explicit user input. For a student-focused long-term memory system, this materially increases privacy risk and potential harm from misclassification, especially because such inferred sensitive attributes can influence future interactions across sessions.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation claims this is 'not a psychological profile,' but the schema immediately defines persistent inferred mood baselines and emotion-linked behavioral patterns. That mismatch is dangerous because it can mislead reviewers and users about the sensitivity of the stored data, undermining informed consent and reducing scrutiny for a profile that is functionally psychological in nature.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger table uses broad, common phrases that can occur during ordinary tutoring, making unintended profile updates likely. In a student-facing memory system, especially one described as long-term DNA, accidental capture can silently accumulate sensitive educational and behavioral data over time.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document is explicitly designed to guide initial profile creation and collect persistent student attributes, but it does not require a clear storage notice, retention explanation, or downstream-use disclosure at collection time. For a system handling student data, this undermines informed consent and increases privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.