Back to skill

Security audit

master-mahasi-sayadaw

Security checks across malware telemetry and agentic risk

Overview

This is a content-only Buddhist meditation teaching skill with scoped citation rules and no hidden persistence, credential access, or local data access.

Install this if you want a Chinese-language Mahasi Sayadaw / Burmese vipassana teaching aid. Be aware it may activate broadly for related meditation topics and may answer in a prescribed Chinese teaching style; it should not replace an in-person qualified meditation teacher, especially for practice problems or claims about attainment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger is explicitly overbroad: it says to invoke whenever a user query merely 'touches' Burmese vipassanā / Mahasi topics, even without an explicit request. That can cause unintended routing, override user intent, and increase the chance that unrelated conversations are steered into this skill's constrained persona and behavioral rules.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill hard-codes a required voice, opening style, and response framing without user opt-in. While not directly a code-execution issue, it can reduce user autonomy, create deceptive impersonation/role-lock behavior, and make the agent less responsive to user preferences or safety-oriented reframing.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The manifest hard-codes response style content in Chinese and does not indicate any user-locale negotiation or fallback. This can override user language expectations, reduce transparency, and in safety-sensitive guidance contexts increase the chance that a user misunderstands instructions or disclosures.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill content is written entirely in Chinese and strongly prescribes a Chinese response style without indicating any user language detection, fallback, or opt-in. This can cause the agent to ignore the user’s preferred language, reducing transparency and usability; in safety-sensitive or nuanced religious guidance, forced language output can also increase misunderstanding of instructions or limitations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.