Back to skill

Security audit

家长沟通助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed parent-communication drafting helper for teachers, with no executable code and clear limits against auto-sending or exposing sensitive student details.

Before installing, confirm this skill is used only in teacher-parent communication workflows and that student workspace consent fields are honored. Avoid using it for generic messaging, and review any generated message before sending, especially when it involves individual learner performance or renewal discussions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill advertises activation on very broad phrases such as '给家长发个消息' and '怎么跟家长沟通', which are common conversational requests and may match situations outside this skill's intended data and privacy boundaries. Unintended activation could pull in student-related workspace data or steer the agent into parent-communication workflows when the user only wanted generic writing help, increasing privacy and integrity risk.

Vague Triggers

Low
Confidence
74% confidence
Finding
The trigger table enumerates broad scenarios but does not define clear scope boundaries separating this skill from general advice, customer messaging, or unrelated communication assistance. That ambiguity can cause over-triggering and context bleed, especially because the skill is connected to shared workspace records involving minors and parent communications.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.