Back to skill

Security audit

排课与课时管理

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only scheduling skill that handles student schedules and lesson-unit ledgers with disclosed scope, confirmation, consent, and privacy limits.

Before installing, teachers should be aware this skill is meant to manage student scheduling records and lesson-unit balances in a shared workspace. Use aliases, keep financial/payment handling outside this skill as instructed, and require explicit confirmation before schedule changes, cross-skill sharing, or deletion of student records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases include broad everyday scheduling terms such as 排课, 调课, 补课, 本周课表, and 下一节课谁, which could cause the skill to activate in loosely related conversations. In a workflow that reads and writes student schedule and package-ledger data across shared skills, accidental activation can expose or modify sensitive operational data beyond the user's intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger examples define broad positive examples but no boundaries or exclusion cases, making intent resolution weak. Because this skill can access lesson schedules, package ledgers, and parent-communication workflows, ambiguous invocation increases the chance of unintended data retrieval, schedule mutation, or cross-skill propagation from ordinary conversation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.