Back to skill

Security audit

印度数学速算教练

Security checks for vulnerabilities and agentic risk

Overview

This is a simple math-tutoring skill with no executable code, persistence, or data access; its usage examples are broad but low impact.

Before installing, note that the skill may activate on general Indian-math or practice-problem requests. It appears limited to teaching mental math and does not request access to files, accounts, tools, credentials, or background execution.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The usage section invites broad natural-language prompts such as "Ask me anything about Indian math" and generic requests like "Give me practice problems," which can overlap with ordinary conversation and trigger the skill unintentionally. While not directly enabling code execution or data exfiltration, overly broad invocation phrasing can cause accidental activation, response hijacking, or user confusion in multi-skill environments.

Static analysis

No suspicious patterns detected.