Security audit
Xueersi Parent Comment Generator
Security checks across malware telemetry and agentic risk
Overview
This is a simple writing helper for parent-school comments and does not request code execution, credentials, network access, or persistence.
Safe to install as a text-generation helper. Users should avoid sharing unnecessary personal details about children and should review generated comments before sending them to a school.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
