Back to skill

Security audit

master-tsongkhapa

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only religious teaching skill with a strong Tsongkhapa/Gelug style, but no hidden persistence, credential use, destructive behavior, or broad system access.

Install this if you want a Tsongkhapa/Gelug-focused teaching assistant. Be aware it may apply a strong doctrinal voice and Chinese-style phrasing on relevant topics, and it can query fojin.app for citations when local excerpts are insufficient.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger condition is explicitly broad enough to invoke the skill whenever a user query merely 'touches' Gelug doctrine, even without an explicit request. This can cause unwanted persona takeover and over-application of the skill, increasing the chance that neutral or mixed-topic conversations are redirected into a constrained ideological or stylistic mode without user consent.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The metadata directs the assistant to answer in 'Tsongkhapa's voice' and to invoke the skill broadly, imposing a fixed persona and style without clear user opt-in. In a religious/doctrinal context, this can mislead users about authorship, reduce transparency, and bias responses toward a prescribed framing rather than the user's preferred tone or neutral presentation.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
These sections prescribe specific forms of address, opening phrases, and a fixed rhetorical register, limiting the model's ability to adapt language and style to user preference. While not directly a code-execution risk, it is a real policy/control issue because it can override user-chosen locale, tone, or accessibility needs and reinforce unwanted persuasive framing.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file strongly constrains responses to a Chinese-language style and formatting regime without any mechanism to respect the user's actual language preference. This can degrade safety and usability because users may not understand important cautions, refusals, or clarifications, especially in a high-context religious instruction skill where nuance matters.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.