Back to skill

Security audit

回译反思法

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese-Vietnamese translation QA workflow with no executable code, hidden data access, or unusual privileges.

Install this if you want a Chinese-Vietnamese translation review workflow. Be aware it may search public sources for terminology and send translation text through selected models, so use extra care with confidential, legal, or customer-sensitive material and explicitly choose separate models for translation and back-translation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README says the skill can be triggered by broad phrases like '回译 / 反思 / 中越翻译 QA / 双模型反思流水线', which overlap with ordinary discussion about translation methods rather than a clear opt-in command. This can cause unintended activation in unrelated conversations, injecting workflow behavior when the user only meant to discuss the topic, reducing user control and potentially causing prompt-context interference.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill’s prompt templates and workflow are written to operate in Chinese and assume Chinese↔Vietnamese processing without offering a language-choice or opt-in mechanism. In a multi-user or mixed-language environment, this can cause unintended language switching, misunderstandings, or incorrect handling of user data and instructions, which is a genuine safety and usability flaw even if not a classic code-execution issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.