Back to skill

Security audit

zhujue-characters

Security checks across malware telemetry and agentic risk

Overview

This skill is a local novel chapter lookup helper; its file access and scripts are disclosed and proportionate, with only content-safety and optional path-override cautions.

Install only if you want a local helper for this specific novel. Leave ZHUJUE_TXT unset unless you intentionally want it to read an alternate chapter directory, and treat retrieved passages as literary source material that may contain offensive language requiring careful context and minimal quotation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Although the skill claims the novel text is self-contained, it documents fallback resolution from the ZHUJUE_TXT environment variable and a fixed host path (/home/jjw/zj/txt). This allows the skill to read content from arbitrary external locations if those paths are present, breaking containment assumptions and potentially exposing unintended local files or host-resident datasets to downstream model context.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The flagged text contains derogatory language and speculation about sexual orientation/gender expression within the imported novel content. Even though it appears as literary source material rather than executable logic, exposing or reproducing such slurs in a skill can propagate harmful discriminatory content, especially if the agent surfaces passages without warning or filtering.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This section repeatedly uses insulting terms aimed at gender nonconformity, which can create discriminatory or hostile outputs if the skill retrieves and presents them directly. In an agent skill, the risk is not code execution but unsafe content generation and normalization of harassment toward protected characteristics.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The content includes additional discriminatory labeling related to gender identity/expression. Because this skill is designed to retrieve novel chapters as background material, the context makes harmful language more likely to be surfaced to users during character analysis, quotations, or Q&A, increasing the chance of unsafe or biased responses.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.