表达教练

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese expression-coaching skill that analyzes user-provided text and suggests rewrites, with no executable code or hidden access requests.

Safe to install for ordinary writing help. Avoid sending sensitive personal, business, or credential-like text unless you are comfortable having that content processed by the platform, and consider invoking it with explicit phrases like '教练' or '润色' to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase “帮我看看” is extremely common in ordinary conversation and is not specific to expression coaching. This can cause unintended activation on unrelated user messages, leading the skill to process content the user did not clearly intend to submit for critique and potentially creating privacy and UX issues.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The condition “消息较长(>50字)且用户明确要求反馈” is underspecified because “明确要求反馈” is not operationally defined. Ambiguous activation criteria can make the skill trigger inconsistently or too broadly, again causing analysis of messages outside the user’s intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal