Back to skill

Security audit

Self Learning Coach v0.1.12

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed learning-coach skill that reads user-provided or authorized materials, creates lesson files, and keeps limited lesson/source tracking notes without evidence of hidden or destructive behavior.

Before installing, be aware that this skill may read authorized internal or local materials you provide and may create HTML lessons plus persistent progress/source index files in the workspace. For sensitive Feishu or company materials, review generated lesson and tracking files before sharing the workspace or forwarding outputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The skill contains conflicting instructions about persistence: it says not to write persistent learning records unless the user asks, but elsewhere directs the agent to create and update workspace tracking files by default. This can cause silent retention of user learning activity, source metadata, and internal material references without explicit consent, creating a privacy and data-governance issue.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The default prompt is broad and maps to a very common user intent ('I want to learn a business'), which increases the chance this skill is invoked in situations where a narrower or different tool should be used. In an agent environment, overbroad triggering can cause unintended access to internal documents, local materials, or workflow-specific content under the guise of learning assistance, creating scope creep and misrouting risk.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill metadata and default prompt hard-code Chinese-language interaction, which can override or conflict with the user's preferred language and reduce transparency about what the agent is doing. In security-sensitive or compliance-heavy business learning contexts, forced language switching can cause misunderstanding of instructions, source material, or consent regarding internal content usage.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.