Back to skill

Security audit

Deploy Skill

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed multilingual Buddhist persona and quote skill with no code execution, credential access, persistence, or hidden data handling, though users should treat its guidance as non-authoritative spiritual roleplay.

Install only if you want an AI Buddhist teaching/persona mode. Treat outputs as generated educational or spiritual content, not as medical, mental-health, legal, crisis, or clergy guidance; for severe distress, self-harm, or mental-health symptoms, use qualified professional or emergency resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The README presents the skill as letting the AI respond 'as Śākyamuni Buddha' but does not clearly warn that it adopts a religious authority persona. This can mislead users into treating outputs as spiritually authoritative guidance rather than generated content, which is more sensitive in contexts involving vulnerable users seeking life advice or meaning.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The README says the AI will automatically switch languages based on the user's language, but it does not describe an explicit opt-in or locale selection policy. Automatic multilingual behavior can cause misclassification, confusion, or delivery of sensitive religious guidance in an unintended language, reducing user comprehension and informed consent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes very broad generic terms such as 'Buddha', 'Buddhism', 'Dharma', and equivalent multilingual variants, which can cause the skill to activate in contexts where the user did not intend to invoke this persona. Unintended invocation can override a more appropriate skill or response path, leading to confusing behavior, incorrect authority framing, or inappropriate spiritualized answers in unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill instructs the agent to automatically choose the reply language based on detected input language, including mixed-language heuristics and fallback behavior, without first confirming the user's preference. This can produce responses in an unintended language, reduce user control, and create reliability and safety issues if the user is discussing sensitive topics and the model answers in a language they do not fully understand.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The persona instructs the agent to default to English for unsupported languages and only then ask whether to switch. That overrides user preference without prior opt-in and can cause unintended disclosure, confusion, or reduced usability in multilingual/sensitive contexts, though it is not an arbitrary code or prompt-injection style compromise.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The templates provide mental-health coping guidance for anxiety and distress across many languages, but they do not warn that the advice is not a substitute for professional or crisis support. In a spiritual-advice skill, users may over-rely on the guidance during acute mental-health situations, delaying urgent care or crisis intervention.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.