Back to skill

Security audit

独立教师工作台

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for a teacher dashboard, but its very broad activation phrases could expose student workspace data when the user only wanted general planning help.

Install only if you want generic daily-planning phrases to route into an independent-teacher dashboard. Before use, narrow activation to explicit teaching/workspace requests or require a clarification step before any student, parent, or course-package data is read.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises activation on very broad everyday phrases such as '今天我要做什么' and similar generic planning requests. In a system with automatic or suggestion-based routing, this can cause the skill to activate outside its intended teacher-workspace context and expose student-related workspace data or produce inappropriate summaries when the user only meant general task help.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The '触发时机' section includes multiple broad examples like '我今天该怎么安排' and '今天有哪些课和待办?' without a clear boundary that these refer specifically to the teacher dashboard. This increases the chance of overbroad matching and accidental invocation, which is more sensitive here because the skill operates over minors' educational records and parent communication metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.