Back to skill

Security audit

master-yinguang

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Buddhist study and citation assistant with limited, purpose-aligned behavior and no hidden installation, persistence, or local data access.

Install this if you want a Chinese-language Yinguang/Pure Land study assistant that answers in a traditional persona and cites Buddhist sources. Be aware it may activate broadly on related Buddhist terms and may prefer its set style unless the host agent overrides it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation criteria are intentionally very broad, including many common religious terms and an instruction to invoke whenever a question merely 'touches' related topics. This can cause the skill to activate for loosely related queries and override user intent or route conversations into a specialized doctrinal persona when not requested.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill mandates a fixed language and stylistic persona ('书信体', '文言白话兼用', strict opening/closing conventions) regardless of user preference. This can degrade user autonomy, create unwanted role-imposition, and increase the chance the assistant ignores explicit requests for a different tone, language, or neutral framing.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill hard-codes Chinese-only address forms and a response style tied to a specific persona without providing any user language preference, fallback, or opt-in. This can cause accessibility and user-consent problems, especially when the broader system or user expects another language, and may lead the agent to ignore explicit user communication needs in favor of skill constraints.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.