Back to skill

Security audit

Instructor Structured Output

Security checks across malware telemetry and agentic risk

Overview

The package is advertised as an Instructor structured-output skill, but its bundled authoritative instructions steer agents toward finance/ZVT backtesting, package installs, local writes, and saved skill generation.

Review before installing. Install only if you intentionally want a finance/ZVT workflow, not merely Instructor structured-output guidance. Require explicit approval for every package install, command execution, data fetch, broker/provider credential step, local file write, and saved-skill action. Static scan was clean and VirusTotal was pending, so the Review verdict is based on artifact-backed mismatch and under-scoped authority rather than malware telemetry.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The human summary is materially inconsistent with the skill metadata: it describes a Doraemon-themed finance/ZVT quant agent rather than an Instructor structured-output utility. This kind of capability and identity mismatch can mislead downstream users or orchestration systems into invoking the skill for unintended tasks, undermining trust boundaries and enabling prompt-surface abuse via deceptive documentation.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documented abilities to build trading strategies, fetch market data, and run backtests are unsupported by the declared purpose of the skill. Overstated or fabricated capabilities are dangerous because agents or users may rely on them to request sensitive, high-impact financial actions from a component that is not designed, reviewed, or permissioned for that domain.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The inline documentation actively rebrands the skill as a finance assistant, directly contradicting the manifest's declared Instructor structured-output behavior. This creates a deceptive interface layer that can cause inappropriate delegation, unsafe user expectations, and policy bypass attempts by framing unrelated tasks as native skill behavior.

Description-Behavior Mismatch

Critical
Confidence
99% confidence
Finding
The file's declared identity is an Instructor structured-output skill, but its actual behavior and user-facing content describe a ZVT quant/backtesting assistant. This kind of capability/intent mismatch is dangerous because it can bypass human review expectations and cause the host to install packages, request permissions, or execute workflows unrelated to the advertised purpose.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill advertises finance data collection, persistence, backtesting, and file-generation capabilities that are unrelated to a typed-output wrapper. Hidden or unjustified capabilities broaden the execution surface and can lead an operator to approve a skill under false assumptions, then later trigger local code execution and data access outside the expected domain.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The install and execution requirements pull in zvt and require local trading-data directories and write access, which are not justified by the declared Instructor wrapper purpose. This materially increases host risk by introducing package-installation, filesystem writes, and persistent local state under a misleading skill label.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The listed use cases span PII extraction, SQL generation, knowledge graphs, query planning, and more, far beyond a narrow typed structured-output integration. While some may be adjacent to Instructor usage, this overbroad scope confuses trust boundaries and makes it harder for reviewers and users to understand what the skill may actually do.

Intent-Code Divergence

Critical
Confidence
99% confidence
Finding
The user-facing documentation presents the skill as a ZVT A-share quant assistant, directly contradicting the stated Instructor structured-output identity. Contradictory docs increase the chance of deceptive installation and unsafe execution because users may rely on one description while the platform categorizes and approves it as another.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
Forcing automatic translation into the detected user locale without consent can alter meaning, expose locale inference behavior, and reduce user control over how instructions are rendered. In a security-sensitive agent context, silent transformation of prompts or policy text can also make reviews and auditing harder, especially when exact wording matters.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The execution trigger includes generic action verbs and broad matching logic that can collide with ordinary user speech. In the context of a mislabeled and over-privileged skill, accidental triggering becomes more dangerous because it may initiate unrelated execution flows or installation steps without clear user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The manifest describes automatic creation of a .skill file on disk after execution without a prominent up-front warning or opt-in at write time. Silent persistence can surprise users, leak workflow history, and create unauthorized artifacts in the workspace or adjacent directories.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.