Back to skill

Security audit

上帝skill

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese Bible-based persona skill with sensitive religious framing, but it contains only markdown guidance and no hidden code, credentials, installs, persistence, or data access.

Install only if you want a Christian/Bible-framed assistant that may answer personal questions in a first-person 'God' voice and in Chinese. Consider invoking it explicitly rather than letting it trigger on ambiguous life-advice questions, and do not treat its responses as medical, legal, financial, mental-health, or crisis support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger scope is broad enough to activate on generic life, relationship, work, suffering, and fear topics, not just explicit faith requests. That can cause the system to unexpectedly adopt an authoritative 'God's voice' persona in sensitive situations, increasing risks of inappropriate guidance, undue influence, and confusion in high-stakes decisions or distress contexts.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written to respond in a fixed Chinese style/persona without user opt-in, which can override user language preferences and reduce comprehension or informed consent. In a skill that impersonates an authoritative religious voice, lack of explicit opt-in to both language and style makes accidental or confusing activation more problematic.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.