Back to skill

Security audit

🎯 思维梯度训练师

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent math tutoring aid, but it directs agents to persist and share detailed student progress data without clear consent or controls.

Review before installing if the user is a student or parent: this skill can create ongoing learning profiles, record mistakes and progress over time, update other learning-history skills, and trigger reminder workflows. It should ideally be used only with explicit consent and clear controls for disabling, deleting, or limiting stored progress data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill instructs activation for very broad scenarios like general math advancement or level testing, which can cause unnecessary invocation and over-collection of student learning data. In an educational assistant, this increases the chance that users are routed into profiling, tracking, or persistent record flows without a narrowly scoped need or clear consent boundary.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation text lists many vague trigger phrases and says the skill should be called whenever a user expresses broad improvement goals, without clear limits. This can override user expectations, lead to excessive skill activation, and funnel routine math help into a system that performs assessment and longitudinal tracking.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes maintaining a persistent 'growth diary' with detailed training history, failed attempts, methods, and semester summaries, but does not present a clear user-facing warning or consent mechanism for retention. Because the context involves students and learning profiles, this creates meaningful privacy risk through unnecessary storage of behavioral and performance data over time.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill specifies automatic weekly updates, archive writes to other skills, and reminder integration without a clear user-facing disclosure or consent flow. Cross-skill propagation of student progress data materially increases exposure, because more components gain access to educational history and inferred weaknesses, amplifying privacy and misuse risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.