Back to skill

Security audit

🧲 物理解题教练

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent physics tutor, but its reference workflows can persist and sync detailed student learning records with only inconsistent consent and retention controls.

Install only if you are comfortable with an opt-in progress-tracking tutor that may store physics mistakes, answers, weak points, and recovery state. Before using it with students, especially minors, confirm that the platform enforces consent, local-only storage when promised, clear deletion/export controls, and a no-storage mode.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The workflow explicitly instructs the agent to generate an error profile, push records into a 'physics error DNA' system, and update a broader 'learning DNA' profile. This goes beyond delivering a single-session physics coaching response and creates cross-system student profiling without any visible consent, minimization, or retention controls in the skill definition.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Updating external 'DNA-style' learner records is not necessary to solve a physics problem and suggests hidden secondary use of student data. Because the document ties ordinary tutoring interactions to broader profiling systems, it increases privacy risk and the chance of unauthorized educational inference or tracking.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The persisted state stores detailed learner history, including subject/chapter, grade, source, errors, model selection, answers, progress, and timestamps. For a tutoring skill, this is more data than is obviously required to answer the immediate question, and the document does not define minimization, expiration, access control, or user visibility.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases include very broad expressions such as being mentally blank or not knowing where to start, which can match many ordinary study interactions outside the intended sub-workflow. This can cause the skill to activate the wrong coaching template, reducing reliability and potentially steering users into an ill-fitting response path.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The exam-cram trigger phrases are broad enough to overlap with ordinary review or planning requests, so the skill may enter a time-compressed 'exam mode' when the user did not intend that workflow. In context, this can suppress deeper guidance and alter archival behavior, producing inappropriate assistance rather than direct security harm.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document describes archiving detailed student problem data and pushing it to other systems, but there is no warning, consent flow, or explanation of retention and sharing. Silent persistence and cross-system transfer of learner data is risky, especially when the users may be minors in a school context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.