Back to skill

Security audit

Learn Cog Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a learning assistant, but it asks for broad write and command execution capability without clear limits or safeguards.

Review this skill before installing. It may be useful for study workflows, but only use it with explicit limits on what files it may read or write, where it may export data, and which commands it may run. Avoid letting it delete or modify files without a clear confirmation step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill is presented as a cognitive-learning tool, but the documentation explicitly classifies it as MD+EXEC and states that some functionality requires command execution. This creates a capability mismatch: a learning assistant should not need broad shell execution, and such excess capability can be repurposed for arbitrary system actions if the agent follows the skill literally.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The documentation says the skill supports broad create/query/export/modify/delete style operations through generic parameters, which significantly exceeds the stated purpose of spaced repetition and recall practice. Overbroad operation claims make it easier for the skill to be used as a general-purpose file/task manipulator, increasing the chance of unsafe actions or abuse.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The file claims the free version is suitable for parsing a single file or task, which broadens the scope from a personal learning tool to generic task/file processing. This ambiguity increases risk because an agent may interpret unrelated user prompts as within scope and perform unintended file operations.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger examples are broad and underspecified, so the agent may invoke the skill for loosely related requests without clear activation boundaries. In a skill that also declares write/exec capability, ambiguous triggering materially increases the chance of unintended or unsafe execution paths.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill declares read, write, and exec capabilities and also mentions create/modify/delete style operations, but provides no warnings, safeguards, or approval flow for actions that may alter files or affect the host system. This combination meaningfully raises the risk of destructive or privacy-impacting behavior from an otherwise benign-seeming productivity skill.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill repeatedly references export, modification, and deletion behaviors but does not explain data loss risk, backup expectations, or any confirmation mechanism. Users and agents may therefore treat data-changing operations as routine, increasing the chance of accidental overwrites, deletions, or unintended disclosure during export.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.