Back to skill

Security audit

菜根谭智慧

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable classical-wisdom guidance skill with broad emotional-wellbeing triggers but no evidence of hidden access, persistence, commands, or data collection.

Install this as a reflective classical-wisdom aid, not as mental-health, medical, legal, or workplace authority. Be aware it may activate on broad mood or stress language; users in serious distress should use appropriate support resources instead of relying on this skill alone.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes broad everyday distress phrases such as '心情不好', '焦虑', '压力大', and '不开心', which can cause the skill to activate in many unrelated conversations. This creates prompt-routing risk: users seeking general emotional support or discussing ordinary mood states may be pushed into this philosophy-specific skill unexpectedly, leading to irrelevant, overly prescriptive, or lower-priority guidance displacing better-matched safety or wellbeing handling.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill relies on a large keyword list without clear precedence rules or disambiguation logic, making activation ambiguous. In agent systems, this can cause unintended invocation, routing conflicts with more appropriate skills, and inconsistent behavior when generic terms like '修身', '处世', or '静心' appear in contexts unrelated to this specific content.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.