AI Learning Tutor

Security checks across malware telemetry and agentic risk

Overview

This is a simple AI learning tutor skill with no executable code, but users should be careful before uploading private study materials.

Reasonable to install if you want a general AI study tutor. Before uploading papers, notes, corporate documents, or personal materials, confirm where they will be processed or stored and use explicit prompts when you want this skill involved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation examples are very broad, natural-language phrases that closely resemble ordinary conversation, which increases the chance of accidental triggering in unrelated chats. That can cause the skill to activate when the user did not explicitly intend to use it, potentially pulling uploaded materials into processing or changing the assistant’s response mode unexpectedly.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill encourages users to upload papers, documents, and study materials to build a knowledge base but does not warn about privacy, confidentiality, or data-handling risks. This is dangerous because users may provide sensitive academic, corporate, personal, or copyrighted materials without understanding the exposure, retention, or sharing implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal