Back to skill

Security audit

master-nagarjuna

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Buddhist study skill that uses local source excerpts and limited FoJin lookup for citations, with no evidence of hidden, destructive, or credential-seeking behavior.

Install this if you want Chinese-language, citation-heavy Nagarjuna/Madhyamaka study assistance. Be aware it may trigger on short or ambiguous Buddhist terms and may favor Chinese output; live FoJin lookup is disclosed and should stay limited to source verification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger scope is unusually broad because it auto-invokes on very common terms such as “空”, “中道”, and any question that merely 'touches' related doctrine. This can cause the skill to activate on loosely related or ambiguous conversations, increasing the chance of inappropriate persona takeover, irrelevant responses, or unintended use of live retrieval paths.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill hard-codes Chinese output requirements ('所有回答必须附经文出处…' and the entire voice/style specification is Chinese-only) without any mechanism to respect the user's preferred language. This can degrade usability, informed consent, and accessibility, especially if the invoking context or user asked in another language; while not a classic exploit, it is a genuine policy and safety issue because it can cause the agent to ignore user intent and produce unusable responses.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.