Back to skill

Security audit

AI Ethics Check - AI 科技伦理审查合规检查

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed compliance checklist tool that sends scored answers to compliancehub.cn only when the user runs the full check, with an offline preview mode available.

Install only if you are comfortable sending your y/n/na compliance answers to compliancehub.cn for scored runs. Use --non-interactive or --non-interactive-json for an offline preview, and store any API key only in the documented environment variable or ~/.config/compliancehub key file.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The manifest advertises cloud scoring, anonymous trial usage, API key handling, and local config writes, but the package metadata itself does not clearly and directly warn users about what data is sent off-device and what local state may be created or modified at execution time. In a skill that processes user-provided compliance answers, this creates a meaningful transparency and consent risk because potentially sensitive business or regulatory information may be transmitted to a third party and persisted locally without sufficiently prominent disclosure in the operational manifest.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.