Back to skill

Security audit

英语听力材料设计

Security checks across malware telemetry and agentic risk

Overview

This is a teaching-design skill for English listening lessons, with disclosed student-profile templates and no executable install or hidden runtime behavior.

Installers should treat this as a Chinese-language teaching assistant skill. Before using it with real students, configure related skills to use pseudonyms, avoid sensitive student identifiers, confirm copyright status for listening materials, and require user confirmation before writing profile data to shared resource or student-analysis stores.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation phrases in the metadata description are broad everyday teaching expressions such as '听力怎么教', '学员听不懂', and '听写训练', with no clear scoping constraints. In an agent ecosystem, this can cause the skill to trigger in unrelated or only loosely related contexts, leading to inappropriate routing, unnecessary data sharing with dependent skills, or the model following the wrong workflow.

Vague Triggers

Low
Confidence
89% confidence
Finding
The '触发时机' section provides only positive example phrases and lacks disambiguation, exclusion criteria, or confidence thresholds. This weak boundary definition increases the chance of accidental invocation, which is especially relevant because the skill interfaces with student analysis and resource workflows, so a mistaken trigger could propagate unsuitable outputs or student-related metadata.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill content is entirely written in Chinese and provides no indication that it will adapt to the user's preferred language or ask for consent before continuing in that locale. While this is not a classic security exploit, it can cause unintended behavior, user confusion, and prompt-routing issues in systems that expect locale neutrality or explicit user choice.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.