Back to skill

Security audit

Knowledge Explainer

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only teaching skill that asks the agent to produce structured explanations and does not request files, credentials, installs, network access, or persistent privileges.

Safe to install for structured concept explanations. Users should be aware it may activate on broad explanation requests and may tend to answer in Chinese unless they specify a preferred language; verify technical derivations or formulas before relying on them for high-stakes work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad, common phrases such as '讲解', '解释', 'teach', and 'knowledge' that can match many ordinary user requests unrelated to this skill’s specialized decomposition workflow. This can cause unintended invocation, overriding a more appropriate skill or injecting an unnecessarily rigid response structure into general conversations.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill metadata and content are written to strongly bias output toward Chinese, with no explicit language negotiation or instruction to follow the user’s preferred language. This creates a usability and policy-alignment issue where the skill may respond in an unexpected language, reducing reliability and potentially causing misunderstandings, though it is not a direct security exploit.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.