Back to skill

Security audit

Dialectical Synthesis

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Chinese-language reasoning prompt skill with low operational risk, though its broad trigger terms could make it activate unexpectedly.

Install this if you want a Chinese-oriented dialectical reasoning aid. Be aware that ordinary phrases like the reported trigger terms may activate it, and set your preferred response language explicitly if you do not want Chinese output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad, generic phrases such as '正反合', '合题', and '对立统一', which are common in ordinary discussion and can cause the skill to activate unintentionally. Mis-triggering is not code-execution dangerous by itself, but it can hijack unrelated conversations, alter assistant behavior unexpectedly, and increase the chance that the model follows this skill when the user did not intend it.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill metadata and content are written entirely in Chinese and strongly frame the skill behavior in that language, which can cause the agent to default to Chinese output even when the user did not request it. This is dangerous because it can override user preference, reduce transparency for non-Chinese-speaking users, and create instruction-following ambiguity when the system should prioritize the user's language and explicit requests.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.