Back to skill

Security audit

domain-knowledge-system

Security checks across malware telemetry and agentic risk

Overview

This skill is a learning-plan generator, but it may also create recurring tracking tasks from broad learning prompts without enough user-control details.

Review this skill before installing if your agent supports scheduled tasks. Use it for explicit domain-learning workflows, and confirm before allowing weekly reports, monthly scans, progress reminders, or generated files. It does not include executable code, but its broad triggers and recurring-task instructions need user control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The README says the skill can be invoked through broad natural-language requests, but it does not define clear trigger boundaries, exclusions, or confirmation requirements. In an agent environment, this can cause accidental activation on loosely related prompts and lead the skill to perform multi-step web scanning and planning actions the user did not explicitly intend.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README advertises '定时追踪配置' and recurring reports/scans without warning the user about persistence, frequency, data sources, or consent requirements. That creates a risk of the agent establishing ongoing monitoring or reminders that surprise the user, consume resources, or collect/update information over time without an explicit opt-in.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are very broad, including generic phrases like '快速入门' and '系统学习', which can cause the skill to activate for many unrelated requests. This creates routing/invocation risk: the agent may invoke this skill when the user did not want a domain-knowledge workflow, leading to incorrect behavior, irrelevant content generation, or accidental collection/planning actions such as scheduled tracking.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to invoke when the user asks to '搭建知识体系、快速入门一个领域、了解陌生领域、系统学习新东西', which is broad enough to match a large class of ordinary educational or exploratory requests. Because descriptions are often used by orchestrators for tool selection, ambiguous invocation guidance increases the chance of unintended activation and inappropriate workflow execution.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill metadata and content are written to produce Chinese-language behavior without stating that output language should follow the user's preference. This can override user expectations, reduce usability, and in multilingual environments cause miscommunication or inaccessible outputs, especially if downstream artifacts like HTML/Markdown are generated in Chinese by default.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.