Back to skill

Security audit

高校招生监控

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate admissions-monitoring skill, but users should review it because it under-explains QQ report sending and persistent cron scheduling.

Install only if you are comfortable reviewing actions before they run. Use manual queries first, keep reports local unless you explicitly choose a QQ recipient, and require the exact cron command plus the removal command before enabling scheduled monitoring.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation says to ask before generating a Word file, but it also states the file will be sent via QQ and deleted afterward without making that outbound transfer and deletion behavior an explicit, informed-consent step. This is dangerous because generated reports may contain sensitive educational targets, query history, or user-requested content, and automatic exfiltration to a third-party messaging service can leak data outside the expected execution environment.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The FAQ tells users that the AI can configure cron to run monitoring automatically, but it does not clearly warn that this creates persistent scheduled tasks that will execute autonomously on the user's system. In an agent setting, silent persistence and recurring execution materially increase risk because users may not realize they are authorizing ongoing background activity, network access, and possible future file writes or notifications.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The FAQ states that the AI can 'help configure and update' schools.json without warning that this changes a local configuration file. This is risky because agent-driven file modification can alter monitoring scope, add attacker-chosen URLs, or overwrite existing settings without sufficiently informed user consent, especially in a tool that performs automated web requests.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.