Back to skill

Security audit

英语综合测评

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a coherent English assessment helper, but it includes writing sensitive student assessment profiles into downstream systems without a clear confirmation or rollback step.

Review this before installing if student records are sensitive in your environment. It should be used in a read-only or draft-review mode unless teachers explicitly approve exactly what CEFR level, profile, and intervention fields will be written back to other systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to activate on ordinary pedagogical discussion such as asking about a student's English level, rather than a clear request to invoke this skill. This can cause unintended routing and execution, exposing student assessment context or causing the assistant to apply the skill when the user only wanted casual advice.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill workflow explicitly includes writing assessment outputs back to another system, but the document does not require an explicit user-facing confirmation before modifying downstream records. In an education context, silent writes can create unauthorized profile updates, propagate incorrect student data, and increase privacy/compliance risk because assessment results are sensitive educational records.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.