Back to skill

Security audit

Spaced Repetition Teaching

Security checks across malware telemetry and agentic risk

Overview

This appears to be a flashcard scheduling skill that updates a user’s own markdown study file, which is expected for its purpose but should be clearly understood before use.

Install only if you are comfortable with the skill reading and editing the markdown flashcard file you point it at. Use a dedicated cards file or folder, keep version control or backups for important notes, and confirm write actions when recording reviews.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill clearly instructs reading and modifying a user-specified markdown file, yet no permissions are declared. Undeclared file read/write capability is dangerous because users and orchestration systems may not realize the skill can alter local data, reducing transparency and consent around data access and modification.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The description understates behavior by presenting the skill as a scheduler while the body specifies in-place modification of the flashcard file and persistent review history updates. This mismatch is risky because it can cause users or policy systems to treat the skill as informational when it actually performs state-changing file operations; the algorithm-version inconsistency also undermines trust and can lead to incorrect study scheduling.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases include broad study-related language such as study sessions and flashcard reviews, which may cause the skill to activate in contexts where the user did not intend file-backed scheduling actions. In a skill that can read and write user files, overbroad activation increases the chance of unintended data access or modifications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal