Back to skill

Security audit

作业设计师

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed teacher tool for designing differentiated assignments, with a purpose-aligned but privacy-sensitive handoff to a student-analysis skill.

Before installing, confirm that your school or organization permits sharing de-identified assignment results with the student-analyzer skill, and avoid entering real names, home addresses, parent identities, or individual score comparisons.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly states that assignment data will be written back to `student-analyzer`, but it does not present a clear user-facing notice or consent boundary at the point of use. Because the skill handles student-derived educational performance data, silent sharing between skills can create privacy, compliance, and data-governance risks even if the document later mentions desensitization.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.