Back to skill

Security audit

Bilingual Buddy

Security checks across malware telemetry and agentic risk

Overview

This appears to be a language-learning skill that openly reformats user text, but users should avoid using it with private or sensitive content.

Install only if you want conversations to be transformed into a bilingual pronunciation format. Do not paste passwords, personal records, private school or child information, or other sensitive text while this skill is active, because it is designed to repeat and expand user input.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes very broad, everyday phrases such as 'bilingual,' '拼音,' and 'language learning,' which can cause the skill to activate in contexts where the user did not explicitly request this formatting behavior. Unintended invocation is risky here because the skill then imposes aggressive formatting and mirroring behavior on all subsequent turns.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill states that every user message must be reformatted into a four-layer bilingual structure before the AI reply, with this as the default behavior rather than an opt-in choice. This can override user expectations, alter the intended response format, and create privacy and usability issues when users did not request translation, transliteration, or phonetic expansion of their content.

Ssd 3

Medium
Confidence
96% confidence
Finding
The requirement to display every user message first in Chinese, Pinyin, English, and IPA forces the assistant to restate and transform all user-provided content in natural language. If a user includes secrets, personal data, credentials, regulated data, or unsafe text, the skill amplifies exposure by repeating and translating it, increasing the chance of accidental disclosure in logs, screenshots, or shared transcripts.

Ssd 3

Medium
Confidence
98% confidence
Finding
The 'must never omit user input' rule creates a persistent data-leak pattern because it requires all user content to be reproduced on every turn, regardless of sensitivity or context. In a learning-oriented skill this is especially dangerous because users, including children, may enter names, contact details, school information, or other personal content that would then be echoed and expanded automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.