Back to skill

Security audit

master-xuyun

Security checks across malware telemetry and agentic risk

Overview

This skill is a purpose-aligned Chinese Chan Buddhism/Xuyun teaching aid with scoped citation and retrieval behavior, not a harmful or deceptive package.

Install this if you want Chinese-language Chan Buddhist answers in a Xuyun-inspired style with scripture citations. Be aware that broad meditation or monastic-discipline questions may route into this specialized religious voice, and live FoJin lookups may send the query text to fojin.app when local excerpts are insufficient.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Confidence
96% confidence
Finding
The activation rule is intentionally broad: it says to invoke whenever a user's question merely 'touches' Chan practice, meditation methods, or monastic discipline, even without explicit request. That can cause unintended routing, persona hijacking of general religious/wellness queries, and reduced user control over whether a specialized doctrinal skill is applied.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill mandates a fixed persona and language style ('本角色口吻作答', specific openings, historical tone) without requiring user opt-in. This can override user preference, create locale/style mismatch, and increase the chance the assistant presents roleplayed religious guidance as authoritative when the user only wanted neutral information.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The manifest hard-codes Chinese as the only supported language, with no indication that the user must opt in or that fallback behavior will preserve the user's language. This can cause the agent to respond in an unexpected language, increasing the risk of misunderstanding, inaccessible guidance, or policy bypass in multilingual contexts, especially because the skill provides practice guidance and doctrinal interpretation.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill hard-codes a highly specific response format and register, including mandatory scripture citations, closing text, and persona constraints, without checking whether the user wants that style. This can override user preference, reduce transparency about system behavior, and cause the agent to answer in an imposed religious/register style that may be inappropriate or manipulative in broader contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.