Back to skill

Security audit

大藏经CBETA2026

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed CBETA Buddhist-text lookup workflow with minor scope and trigger-quality issues but no hidden, destructive, or sensitive behavior.

Before installing, understand that this skill is designed to answer from a specific CBETA knowledge base. For scholarly commentary beyond CBETA, ask the agent to clearly separate external sources or state when the CBETA corpus does not cover the request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill claims a single CBETA knowledge base as its only source, yet instructs the agent to extract 'modern scholars' views,' which are unlikely to exist in that corpus. This mismatch can cause the agent to hallucinate unsupported material or quietly pull from unauthorized sources, undermining provenance guarantees and citation integrity.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document is internally inconsistent: it promises 'only CBETA' and 'single-library precision search' while also requiring outputs beyond that library's scope. Self-contradictory instructions are dangerous because they create undefined behavior at decision time, increasing the chance of fabricated claims, policy bypass, or inconsistent source attribution in research-grade responses.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger list is broad enough to match common Buddhist terms and general discussion topics, which can cause accidental invocation outside the user's intent. Unintended activation can override a better-suited skill, distort answers toward this skill's rigid workflow, and increase the risk of irrelevant tool use or provenance claims.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.