Buddha Companion

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese Buddhist reflection assistant with no code execution, data access, credentials, persistence, or hidden install behavior.

Install this if you want Chinese-language Buddhist/philosophical reflection. Treat it as spiritual guidance, not professional mental health, medical, legal, or financial advice, and be aware it may frame ordinary life concerns through Buddhist practice concepts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition '当用户问佛法问题、修行困惑、或在生活中遇到境界时触发' is broad enough to match many ordinary reflective or emotional conversations, which can cause the skill to activate outside clearly intended scope. Over-broad invocation can lead to unwanted steering of user conversations into spiritual counseling style responses, reducing predictability and potentially creating safety issues in sensitive contexts.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill metadata and behavior are defined entirely in Chinese and implicitly assume Chinese-language interaction without documenting a locale boundary or fallback behavior. This can cause mismatched responses for users speaking other languages, increasing misunderstanding and making activation behavior less predictable, though it is not inherently dangerous in the same way as code execution or data exfiltration.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal