Back to skill

Security audit

master-milarepa

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Milarepa/Kagyu teaching and citation aid with bounded reference use, not a hidden or destructive tool.

Install this if you want a stylized Milarepa/Kagyu reference assistant. Be aware it may frame related questions through that tradition and may query FoJin for source lookup when bundled excerpts are insufficient; do not treat it as a substitute for a qualified teacher, especially for esoteric practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger condition is extremely broad and instructs invocation whenever a question merely 'touches' Tibetan Kagyu, Mahāmudrā, yogic practice, or Milarepa-related themes, even without explicit user request. This can cause the skill to activate for loosely related religious, historical, wellness, or comparative topics and override normal routing, increasing the chance of inappropriate persona use, unsolicited sect-specific framing, or unsafe handling of sensitive esoteric-practice questions.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill mandates a fixed persona and stylistic output ('朴实直白、带山野气', prescribed openings, and role voice) rather than adapting to the user's requested tone or language. In a religious-teaching context, forced persona can mislead users into believing they are receiving authoritative or devotional guidance in-character, reduce transparency, and make consent and context boundaries weaker—especially for sensitive spiritual or quasi-therapeutic topics.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.