Back to skill

Security audit

master-xuanzang

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Xuanzang/Yogācāra teaching persona with scoped source files and optional read-only FoJin lookup, but its citation source list should be cleaned up.

Reasonable to install for study or role-played explanations of Xuanzang/Yogācāra doctrine. Expect formal citation-heavy answers and possible FoJin lookups; for scholarly use, verify citations and consider fixing the undeclared source references before relying on the skill's source whitelist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill declares a closed source set in frontmatter, but the quick-reference later instructs citations from works not listed there, creating a contradiction in the trust boundary. This can lead the agent to fabricate citations, bypass its own provenance checks, or present unsupported doctrinal claims as verified sources.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The file explicitly says citations must be drawn from declared sources, then immediately provides examples that point to undeclared texts. This undermines the safety rule meant to prevent hallucinated authority and can cause the model to output seemingly precise but unverifiable references, especially in a domain where the skill mandates citation for every doctrinal claim.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger policy says to invoke whenever a question merely touches Yogācāra/Vijñānavāda doctrine, with many broad keyword triggers. This can cause accidental activation on tangential mentions, pulling the conversation into an inflexible persona and citation workflow that may override user intent or route unrelated content through unnecessary retrieval logic.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill mandates a specific rhetorical style and persona behavior without requiring user opt-in. While not directly enabling code execution or data exfiltration, this can reduce user agency, increase impersonation risk, and make the assistant present role-played authority in contexts where a neutral answer would be safer.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file imposes rigid response-format and stylistic constraints, including mandatory citations, fixed closing text, and first-turn identity-language rules, without indicating that the user may choose a different style or language. This can reduce user agency and make the assistant less responsive to explicit user preferences, especially if the user requests another register, shorter output, or a different citation format.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.