Back to skill

Security audit

诗遇 Poetry Resonance

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Chinese-poetry assistant with disclosed local study tracking and optional, narrowly scoped external lookups.

Install this if you want a Chinese-poetry skill and are comfortable with it saving preferences and learning progress locally. For maximum privacy, avoid enabling weather or poem verification lookups, or ensure only city names and poem-related terms are sent externally as the skill specifies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Ae1

High
Category
analysis-evasion
Content
- `references/libai_raw.json` · **底库一**:李白全集 1149 首(数据来自 chinese-poetry 项目全唐诗,繁转简,MIT 协议),用于原文核对与全集检索。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `references/poets_selected.json` · **底库二**:杜甫 70 首 + 苏轼词 44 首(chinese-poetry 全唐诗/全宋词,繁转简,按代表作清单精选;其中 2 首数据源缺失由人工补录通行版,字段 `_manual` 标记)。苏轼条目含 `rhythmic` 词牌字段,日
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `references/poets_profile.md` · **诗人档案**:李白/杜甫/苏轼人生阶段线(每阶段:时间/关键词/代表作/情绪底色+一句话主线)。模式 B 拆解时先定位诗人当时所在阶段,背景自动挂上"人生坐标";日签推荐理由可用阶段梗。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `references/poets_profile.md` · **诗人档案**:李白/杜甫/苏轼人生阶段线(每阶段:时间/关键词/代表作/情绪底色+一句话主线)。模式 B 拆解时先定位诗人当时所在阶段,背景自动挂上"人生坐标";日签推荐理由可用阶段梗。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `references/seal_qr.svg` · **印章二维码**:指向 ClawHub 页面的真码(红底白模块、中心"诗遇"、H 级容错),日签卡片固定嵌入、直接复用。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `references/seal_qr.svg` · **印章二维码**:指向 ClawHub 页面的真码(红底白模块、中心"诗遇"、H 级容错),日签卡片固定嵌入、直接复用。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

External Transmission

Medium
Category
Data Exfiltration
Content
## 权威核对与外部服务(可选,联网时)

- **搜韵开放 API**:`https://api.sou-yun.cn/open/poem?key=<诗名或诗句>&scope=Title|Sentence&jsonType=true`(非商业用途,无需 key 鉴权)。返回含原文、历代笺注(《古今诗话》《诗薮》等带出处)、体裁、韵部——可用于:版本异文核对、模式 B 深读档的笺注素材(取 1-2 条译成人话,翻不出人话宁可不用)。
- **wttr.in 天气**:`https://wttr.in/<城市拼音>?format=j1`(免 key,开源)。模式 C 日签天气关联层使用。

**硬约束(数据边界)**:外部查询只允许以**诗名/作者/诗句/城市名**为关键词,**严禁将用户个人描述、经历原文、学习进度、文案内容发送给任何外部 API**。API 不可用或离线时静默跳过,不影响任何模式(零依赖底座)。
Confidence
50% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
This JSON file contains only Chinese-language poem content and metadata, with no natural-language indication that the locale is optional or user-selectable. Under the policy rule for language/locale constraints, a file that effectively fixes output/content to a specific language without opt-in can be considered a policy violation unless clearly documented as region-specific.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains substantive natural-language content in Chinese, but does not indicate that the user can choose the language or that the skill is intentionally scoped to a Chinese-language audience. Under the policy rule for language or locale constraints, forcing a specific language without opt-in can be a violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The file’s source, note, titles, and poem content are entirely in Chinese, indicating a hard-coded language/locale for the skill data. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is provided in the file.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, including the usage guidance section. Under the policy criteria, forcing a specific language without offering user choice can be a natural-language policy violation unless the locale constraint is explicitly documented and justified, which it is not here.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The natural-language metadata in the SVG is entirely in Chinese and presents the skill/install description in a single language. For a general-purpose skill asset, this can conflict with language/locale policy when no user choice, fallback, or justification is provided.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.