Back to skill

Security audit

master-ajahn-chah

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Buddhist teaching/reference skill with broad activation and persona caveats, but no evidence of unsafe data access, persistence, or destructive behavior.

Install this if you want answers framed through Ajahn Chah, Theravada, and Thai Forest sources. Be aware that broad terms like mindfulness or meditation may trigger this tradition-specific voice even when you wanted a neutral answer, and occasional live lookup may contact FoJin only for declared source gaps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger criteria are intentionally expansive and include generic mindfulness and meditation terms, plus an instruction to invoke even without explicit request. This can cause the skill to activate in contexts where the user did not ask for a Theravada/Ajahn Chah framing, leading to unwanted persona steering, reduced user autonomy, and potential misrouting of unrelated mental-health, religious, or general wellness queries.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill mandates a fixed persona and stylistic framing ('人格签名') without user opt-in, which can override the user's preferred tone, tradition-neutral framing, or desire for plain factual answers. In a religious/spiritual domain, forced voice and framing increase the risk of undue influence, confusion between source material and roleplay, and answers that feel authoritative beyond what the user requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.