Back to skill

Security audit

master-fazang

Security checks across malware telemetry and agentic risk

Overview

This is a coherent educational Huayan/Fazang teaching skill with scoped citation and retrieval rules, not a skill that seeks sensitive access or performs harmful actions.

Review the broad auto-trigger terms and Chinese-focused style before installing. The skill may answer in a specialist persona for Huayan-related terms, and it may contact fojin.app only when local excerpts are insufficient for declared sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger policy is explicitly broad enough to invoke on many common Huayan/Buddhist doctrinal terms, including generic phrases such as '法界'. That can cause the skill to activate when the user did not actually request this specialist persona, increasing the chance of unwanted instruction takeover, incorrect routing, or unnecessary use of the skill's restrictive behavior rules.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hard-codes response behavior in Chinese and prescribes fixed forms of address without preserving user language preference or accessibility needs. This can cause unintended exclusion, reduce usability for non-Chinese-speaking users, and create policy-compliance issues when the user expects responses in another language.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.