Back to skill

Security audit

master-zhiyi

Security checks across malware telemetry and agentic risk

Overview

This is a scripture-study voice skill with scoped citation and lookup behavior, with minor usability caveats around broad activation and Chinese-first style.

Install this if you want a Chinese Tiantai/Zhiyi study assistant that cites Buddhist source texts. Be aware it may activate on adjacent Tiantai topics and may answer in a Chinese/classical style unless the host agent or user steers language preference.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger condition is intentionally expansive: it says to invoke whenever a user's question merely 'touches' Tiantai doctrine, even without explicit request. Over-broad activation can cause the skill to take over adjacent conversations, increasing the chance of unwanted persona/style injection, unnecessary tool use, or answering outside the user's intended scope.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill content is entirely written as a Chinese-only voice/style specification and includes multiple mandatory response rules in Chinese, with no indication that the user explicitly opted into Chinese output. This can override user language preference, reduce transparency and usability for non-Chinese-speaking users, and cause misunderstanding of safety-critical disclaimers or limitations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.