English Assessment

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent English assessment skill, though users should know it saves local test records and may use web search for questions.

Install only if you are comfortable with assessment answers and performance history being saved in local /tmp files. Avoid entering sensitive personal, school, or work-confidential text as answers, and remove /tmp/english-assessment-wrong.json and /tmp/english-assessment-history.json if you want to clear stored data.

SkillSpector (3)

By NVIDIA

Vague Triggers

Medium
Confidence
79% confidence
Finding
Overly broad trigger phrases can cause the skill to activate unintentionally during unrelated conversations, leading to unexpected state changes and collection/storage of user answers. In this skill, accidental activation is more concerning because it can begin a session that persists wrong answers and score history to local files.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill persistently stores wrong answers, explanations, scores, and progress history in local files without an explicit user-facing notice or consent flow. This creates a privacy risk because users may disclose educational performance data and free-text answers without understanding that the information will be retained across sessions.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
Allowing network searches for test content without warning users introduces an undisclosed external data-transfer path. Even if the intent is only to fetch questions, user context or session metadata may be transmitted to external services, increasing privacy and supply-chain risk.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal