Back to skill

Security audit

用间隔重复与主动回忆结构化追踪学习

Security checks across malware telemetry and agentic risk

Overview

This learning skill should be reviewed because it asks for command execution, file writing, and broad API/file capabilities without clearly limiting them to learning tasks.

Install only if you are comfortable granting a study assistant access to read and write files and potentially run commands. Keep it constrained to non-sensitive learning materials, avoid providing real API keys unless the destination service is clear, and require explicit approval before any file modification, external API call, or shell command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a learning assistant, but its documentation claims broad file handling, API integration, and command execution capabilities unrelated to that purpose. This capability mismatch increases the risk that an agent or user will authorize powerful operations under a benign-seeming label, enabling unnecessary access to local files, external services, or the host system.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
Advertising command execution in a skill whose stated purpose is spaced repetition and active recall is dangerous because it normalizes shell access without a clear business need. In an agent environment, this can lead to arbitrary command execution, filesystem changes, process spawning, or abuse of inherited credentials if the skill is invoked with excessive trust.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
External API integration is not inherently unsafe, but here it is presented broadly without clear necessity for the learning-assistant function. That ambiguity can result in sensitive learning content, local file contents, or metadata being sent to third-party services without users fully understanding the disclosure or trust boundary.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes write, API, and command-execution capabilities without clear nearby warnings about modifying files, contacting external services, or affecting the host system. In practice, this weakens informed consent and increases the chance that users invoke impactful operations believing the skill is only a benign study tool.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.