Back to skill

Security audit

英语口语活动设计

Security checks across malware telemetry and agentic risk

Overview

This is a coherent teaching-support skill with no executable code, but users should handle student recordings and profiles with clear consent and retention rules.

Installers should treat this as a classroom-planning aid, not an automated assessment or data-processing tool. Before using student recordings or speaking profiles, obtain appropriate student or guardian consent, de-identify records, restrict access, and set a deletion schedule.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation examples in the metadata are broad, everyday teaching phrases and do not include clear exclusion criteria or routing constraints. In a multi-skill environment, this can cause unintended invocation, leading the assistant to select this skill when the user intended a different teaching, assessment, or student-analysis workflow.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger table defines activation scenarios using generic phrases like '口语课怎么上' and '学员口语弱', which are too ambiguous for reliable routing. This increases the chance of over-broad activation, potentially surfacing the wrong skill and causing workflow confusion, incorrect data handoff, or bypass of more appropriate specialized skills.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The rubric explicitly asks teachers to prepare student speech recording samples for review, but it provides no privacy, consent, retention, or access-control guidance. Because this skill is designed for educational use with identifiable learner performance data, including likely minors, the omission can lead to unauthorized collection, storage, or sharing of sensitive student voice data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.