Back to skill

Security audit

mao-skill

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Mao writings reference skill with no code execution or data access, though its knowledge base has accuracy and neutrality limitations.

Safe to install from an agent-security perspective. Treat it as a study aid rather than an authoritative reference: verify citations, volume placement, and historical claims against primary editions or independent scholarship, especially because the skill uses a fixed interpretive stance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The file claims comprehensive coverage of Volumes 1-4, but the body itself includes misclassified, duplicate, and explicitly out-of-scope entries. In an agent skill that is meant to answer factual questions from this knowledge base, this can systematically mislead outputs and create integrity failures, especially when the model is instructed to prefer this file over its broader knowledge.

Intent-Code Divergence

Low
Confidence
89% confidence
Finding
The section heading states Volume 2 contains 14 pieces, but more items are enumerated. This is a data integrity flaw rather than code execution risk, but in a retrieval-oriented skill it can cause incorrect counting, bad citations, and reduced trust in generated answers.

Intent-Code Divergence

Low
Confidence
87% confidence
Finding
The heading for Volume 3 claims 19 pieces, but fewer are listed. This inconsistency weakens the reliability of the knowledge base and can lead the agent to present incomplete coverage as exhaustive, which is dangerous in a reference skill intended for authoritative historical answers.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The Volume 4 section is materially inconsistent: it claims 15 pieces, lists 22, and even includes entries explicitly noted as outside Volume 4. In a skill context, this substantially increases the chance of false attribution, incorrect chronology, and authoritative-sounding but wrong answers, making the content integrity problem more severe than a simple typo.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.