Back to skill

Security audit

Spec Flow

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language documentation workflow skill that reads project context and writes planning files, with no hidden execution or credential behavior found.

Before installing, users should be comfortable with the skill reading local project structure and writing .specify planning documents. It is intended for Chinese-language output; users who need another language may need to adapt the templates or override that preference explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
Line L103 states '全程使用中文编写', which imposes a fixed language requirement on the user and the skill output. The file does not offer a language choice or document a justified region-specific need, so this is a natural-language policy violation under the language/locale rule.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This markdown file presents all operational guidance exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or alternative language option is provided. The file does not indicate that the skill is region-specific or otherwise justified to require Chinese-only usage.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The template content is written entirely in Chinese and includes directives such as 'plan 只回答怎么做', which implicitly requires use of a specific language/locale. Under the policy, forcing a language without user opt-in or documented justification is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown template is written entirely in Chinese and includes fixed Chinese field labels and instructions, which effectively imposes a specific language on downstream skill/spec authors. The file does not offer an opt-in language choice or explain a justified region-specific requirement, which fits the language/locale policy violation category.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This markdown template is entirely written in Chinese and does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.