Back to skill

Security audit

造化(Zaohua)· AISoul Forge

Security checks across malware telemetry and agentic risk

Overview

This skill locally creates and tests fictional AI persona packages, with no evidence of hidden network access or credential handling.

Install this if you want a local helper for creating and testing fictional AI persona packages. Be aware that it may be auto-selected for AI personality or companion requests, can write generated files under a workspace/output directory, and can role-play as a generated Soul during trial chat. Do not use it to clone real people, and review generated packages before sharing or importing them into another agent host.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest enables implicit invocation with a very broad default prompt and no visible gating or scope constraints, which can cause the skill to be auto-selected for loosely related requests. Because this skill can create and simulate AI personalities, unintended invocation could expose users to impersonation-adjacent behavior, confusing outputs, or policy-sensitive generation in contexts where the user did not explicitly request it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.