Back to skill

Security audit

📐 数学解题教练

Security checks across malware telemetry and agentic risk

Overview

This math tutoring skill is coherent, but it should be reviewed because it can process student photos and automatically read or write learning-profile records without clear consent controls.

Review before installing in environments with students or minors. The tutoring behavior is not inherently unsafe, but admins should require clear consent, image redaction guidance, limits on OCR/multimodal processing, and controls to inspect, disable, or delete learning-profile and error-history records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The instruction that math-related scenarios should '务必调用此SKILL' is overly broad and can cause the agent to invoke this skill in many ordinary conversations without verifying necessity or user consent. In practice, this can degrade routing quality, crowd out safer or more appropriate skills, and increase unnecessary handling of student data and images.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation examples cover a wide range of common student utterances without scope limits, making accidental invocation likely. Because the skill also prescribes persistent follow-up and cross-skill linkage, broad triggering can expand data use and steer conversations into a more invasive workflow than the user intended.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill discusses uploading problem images and OCR/visual parsing, but only notes technical dependencies and does not warn about privacy implications. Students may send photos containing names, school identifiers, handwritten notes, or other sensitive information without informed consent, leading to avoidable exposure through multimodal processing or external OCR services.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly describes reading from and pushing to student error-history and DNA-style records across other skills, but provides no user-facing disclosure, consent mechanism, or data minimization controls. Cross-skill profiling of a student's mistakes and performance can reveal sensitive educational patterns and create unauthorized secondary use of personal data.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are very broad and can activate the math workflow for loosely related phrases like '发来题目/说做错了/说不会做', increasing the chance of unintended routing. In an agent setting, over-broad activation can suppress user intent, cause unnecessary OCR or stateful tutoring flows, and interfere with other skills that would be more appropriate.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The entry-condition examples are underspecified and permissive, allowing the skill to claim conversations with minimal context such as generic help requests about a problem. This can lead to misfires, incorrect skill selection, and user-friction loops where the agent insists on the tutoring workflow even when the user wants something else.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.