Back to skill

Security audit

AI 书童

Security checks across malware telemetry and agentic risk

Overview

This is a broad study and Obsidian note-management skill whose file updates, study tracking, reminders, and web search are disclosed and fit its purpose.

Install this if you want an assistant that can manage a dedicated Obsidian study vault, create and update notes, track review performance, set study reminders, and search the web for resources. Before use, confirm file deletions, bulk note changes, exports, scheduled reminders, and any searches involving sensitive study topics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list contains many broad, everyday phrases such as “提问”, “追问”, “找到”, and exam-related phrases that can appear in normal conversation, making accidental activation likely. In this skill, unintended activation is more dangerous because the skill is designed to access web search, manage an Obsidian vault, and automatically create or update notes, which can lead to unexpected tool use or data modification.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents automatic updates to MOC.md whenever notes are created or deleted, but does not clearly warn the user that files in their local vault will be modified. This is risky because users may invoke the skill for reading or study help without realizing it can perform persistent changes to their note repository structure and indexes.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that answer data and weak knowledge points are automatically persisted, but it provides no privacy notice, retention policy, or user control over this stored study history. Because the stored data may reveal exam preparation, weaknesses, and personal learning patterns, silent persistence increases privacy risk and the chance of unwanted long-term profiling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.