Back to skill

Security audit

数学教案设计

Security checks across malware telemetry and agentic risk

Overview

This is a math lesson-planning skill with disclosed educational data flows and no executable code or hidden install behavior.

Before installing, make sure teachers use pseudonyms for student records and confirm any linked student-analysis or resource-library skills follow your school’s data-sharing rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance uses very broad, common teaching phrases such as asking how to explain a concept or write a lesson plan, without clear constraints on when this skill should or should not be invoked. In an agent ecosystem, this can cause over-triggering and unintended routing of general educational conversations into this skill, increasing the chance of inappropriate data sharing with connected skills or low-quality task delegation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger table enumerates ambiguous scenarios like 'concept how to teach' and 'student cannot solve problems' without scope boundaries, role checks, or disambiguation rules. Because this skill also interfaces with student analysis and resource systems, ambiguous invocation can unintentionally pull teacher or student context into downstream workflows that were not necessary for the user's request.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.