Back to skill

Security audit

试听与学员建档

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed student-intake workflow, but it handles minor/student records and has a real ambiguity about whether risk labels are stored or only derived.

Install only if you are comfortable using it for student intake records in a shared workspace. Before use, decide whether risk markers are allowed to be stored or must remain derived-only, require guardian consent for any identifiable minor data, prefer pseudonyms, and avoid writing contacts or real names into shared dashboards unless strictly necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill contains contradictory instructions about whether 'risk markers' are written back to solo-dashboard or only exposed as a derived, non-stored view. In a workflow handling minor/student records, this ambiguity can lead downstream agents or operators to persist risk classifications unexpectedly, or to assume they are not stored when they actually are, creating privacy, retention, and compliance issues.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are very broad and lack negative conditions or scope checks, so the skill may activate during ordinary teaching discussions that merely mention trials, follow-up, or student records. Because the skill handles student intake and cross-skill data sharing, accidental activation can cause unnecessary collection, profiling, or writing of student-related data into shared workspace structures.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The template encourages collecting and persisting student profile data, including scheduling, learning assessment, source history, and a linkage indicating the record is written into a dashboard, but it provides no privacy warning, data-minimization guidance, or handling instructions for identifiable student information. In an education context involving minors and parents, this omission can lead users to store personal data unnecessarily or insecurely, increasing privacy, compliance, and unauthorized-disclosure risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.