Back to skill

Security audit

The Middle Way (中庸 Zhongyong)

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable decision-making skill that teaches a middle-way analysis method and does not request sensitive access or perform actions on the user's system.

This skill appears safe to install as a thinking aid. Expect it to guide the agent through structured questions about tradeoffs and sometimes include historical Chinese source material in examples, but it does not add system access or automation authority.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
This markdown file contains substantial Chinese quotations alongside English translation, but it does not indicate whether multilingual presentation is optional or expected for the user. Under the policy rule for language/locale constraints, forcing a specific language presentation without opt-in can be a natural-language policy concern.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.