Back to skill

Security audit

💡 数学概念解释器

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language math tutoring skill made of markdown guidance and examples, with no executable code or hidden data access found.

Install this if you want a Chinese-language math concept explainer. Be aware it may trigger broadly for math-understanding questions, and any learning-progress updates or reminder creation should be confirmed by the user or governed by the connected skills' controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation guidance is unusually broad: it says to invoke the skill for essentially any math-concept understanding, formula-principle question, or geometry visualization request. In an agent setting, this can cause over-triggering and reduce correct skill routing, leading to inappropriate handling of user requests or unintended suppression of more suitable tools, though it is not directly malicious.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill metadata and behavioral guidance are entirely Chinese-centric and do not offer language negotiation or document that the skill is intentionally limited to Chinese-speaking users. In multi-user or multilingual agent environments, this can produce inaccessible or confusing outputs, causing denial of effective service for users who do not understand Chinese and potentially interfering with safe, user-aligned interaction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.