协同养育操作系统

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed co-parenting/family-support prompt skill, but its activation wording is broader than ideal for a sensitive topic.

Install only if you want an assistant to provide co-parenting or post-divorce family-support framing. Because the trigger terms appear broad, review or narrow them if you do not want the skill to activate on casual mentions of an ex, relatives, custody, or family conflict. Do not treat the skill as legal, custody, child-safety, or therapy advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README states that merely mentioning broad topics like divorced-family parenting, co-parenting, or pickup arrangements will auto-trigger the skill. This can cause unintended activation in loosely related conversations, exposing sensitive family-conflict guidance in the wrong context and potentially overriding a more appropriate assistant behavior. Because the domain involves high-sensitivity personal and family matters, overbroad triggering is more dangerous than in a generic productivity skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The top-level description says the skill should trigger for broad topics like '前任矛盾' and related family issues without clear exclusion criteria. That can cause the skill to activate outside true co-parenting scenarios, steering unrelated conversations into sensitive family-conflict framing and potentially producing inappropriate guidance in emotionally charged contexts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad, high-frequency terms such as '前任', '奶奶', and '抚养', but does not define boundaries or non-trigger cases. In a general assistant environment, this can lead to over-activation on ordinary relationship or family discussions and expose users to misclassified support flows, especially around conflict, legal, or child-safety-adjacent topics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal