Back to skill

Security audit

Mao Emperors

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese strategy persona skill with broad ideological framing, but it does not request tools, credentials, persistence, or hidden execution.

Install this only if you want advice framed through Maoist philosophy and Chinese imperial-history personas. Invoke it explicitly for brainstorming, treat the output as perspective rather than authority, and require separate confirmation before pairing its recommendations with action-capable skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill is written entirely in Chinese and frames the agent persona, dialogue style, examples, and outputs in Chinese without offering any user-selectable language preference. This can override user expectations or system defaults, causing prompt steering, accessibility issues, and reduced usability for non-Chinese-speaking users; while not a direct code-execution risk, it is a real policy/interaction vulnerability because it constrains model behavior without consent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains broad, generic phrases such as '战略分析', '组织设计', '实践论', and '矛盾论' that could match ordinary user requests not specifically intended for this skill. In a multi-agent decision-making skill, unintended activation can route users into a strong ideological framing and generate advice under the wrong context, increasing the chance of confusing, biased, or inappropriate outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.