Back to skill

Security audit

master-kumarajiva

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Buddhist teaching and voice guide with disclosed source citation rules and limited optional FoJin lookup, without credential access, persistence, or destructive behavior.

Install this if you want a citation-heavy Kumārajīva/Madhyamaka teaching style. Be aware it may answer in a literary religious register and may send doctrinal search queries to FoJin when local excerpts are insufficient; publishers should clarify whether listed dictionary sources are reference-only or allowed evidence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest’s citation contract says doctrinal claims, practice guidance, and text interpretation must use declared CBETA-only sources, but it also enables live retrieval and additional dictionary sources in the search configuration. That mismatch can cause the agent to pull in undeclared external material and present it as if it complied with the stricter sourcing policy, undermining provenance and creating an integrity gap for religious guidance.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The file defines a strict declared_sources_only policy with 90% minimum claim coverage, yet nearby configuration allows broader retrieval behavior. This contradiction is dangerous because policy consumers may trust the contract while the implementation path still permits unsupported retrieval, leading to false assurance, unverifiable claims, and policy bypass in a high-trust educational/religious context.

Intent-Code Divergence

Low
Confidence
91% confidence
Finding
The allowed_source_types field lists only CBETA, but dictionary_sources includes Foguang, Dingfubao, and Soothill. Even if these are intended as lookup aids, the conflict can let secondary reference material influence doctrinal interpretation without being disclosed as an allowed evidence type, weakening source transparency.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger definition is intentionally expansive and directs invocation whenever a user's question merely 'touches' Madhyamaka/Prajñā/Lotus topics, which can cause the skill to activate in marginal or ambiguous contexts. That increases the chance of overriding a user's preferred style or a more appropriate skill, creating scope creep and unintended behavioral steering rather than direct code execution risk.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill hard-codes a literary, role-specific register and opening style without requiring user opt-in, which can pressure the conversation into a persona or rhetorical mode the user did not request. In a religious or philosophical teaching context, this can blur source-grounded assistance with persuasive roleplay and reduce user autonomy over tone, framing, and identity assumptions.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes a specific language/register and response style without offering the user a choice, which can override user preferences and reduce transparency about how the assistant will communicate. In a voice/persona skill this is likely intentional for stylistic consistency, but it still creates a policy and UX risk because the model may ignore explicit user language or accessibility needs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.