Back to skill

Security audit

📊 每周学习复盘

Security checks across malware telemetry and agentic risk

Overview

This weekly learning-review skill is coherent and disclosed, with minor privacy and routing caveats around broad triggers and cross-skill learning summaries.

Before installing, confirm you are comfortable with a weekly review skill summarizing learning activity from related skills and optionally producing a family-facing version. Use it when the student explicitly wants a weekly review, and be careful with sharing reports that include emotional, stress, or crisis-related observations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description includes broad trigger phrases such as “总结一下这周” and especially “下周重点是什么”, which can plausibly appear in normal conversation outside the intended weekly-review flow. In an agent ecosystem, overly broad activation criteria can cause unintended skill invocation and unnecessary access to learning-history data, increasing privacy and routing risk even without explicit malicious logic.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger table mixes weekly review with broader scenarios like monthly summary, exam prep, and generic milestones, making the skill boundary unclear. This can lead the orchestrator or runtime to invoke the skill for tasks outside its stated scope, causing inappropriate data aggregation or bypassing more specialized skills and consent boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.