Back to skill

Security audit

Daily Xuanzang

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent daily historical-reading skill, but users should understand that it persists reading progress, can archive generated media locally, and may reproduce biased historical source passages.

Install if you want a stateful daily reading workflow. Before using voice output, inspect or provide the referenced xuanzang-audio.sh script yourself. Be aware that the skill writes progress and replay files locally, and that some original historical passages may need contextual framing when translated or read aloud.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill directs the agent to execute an external helper script from a workspace path outside the skill bundle, including a user-home example path. This expands trust to mutable, out-of-band code that could be replaced or tampered with, enabling unintended command execution under the guise of audio generation.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list includes very generic terms such as 'xuanzang' and the canonical text names, which can cause unintended invocation during ordinary conversation or scholarly discussion. In a stateful skill that auto-tracks and advances reading progress, accidental activation can lead to confusing behavior and unintended state changes even without explicit user intent.

Missing User Warnings

Low
Confidence
72% confidence
Finding
The README advertises automatic progress tracking but does not clearly warn users that using the skill may modify persisted reading state. When combined with broad triggers and automatic advancement in the delivery flow, users may have their reading position changed unexpectedly, which is a consent and integrity issue for stored user state.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This passage assigns fixed negative physical and behavioral traits to the people of an entire country, presenting population-wide stereotyping as factual description. In a user-facing reading skill, reproducing such claims without contextualization can normalize ethnic or national prejudice and expose users to harmful biased content.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This finding reflects a broad moralized claim about a population's inherited nature and violent disposition. Even though it appears in a classical religious-historical text, surfacing it unqualified in a modern skill can reinforce dehumanizing narratives about ethnicity or regional identity.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The text repeatedly characterizes entire regional populations with negative moral and behavioral attributes such as deceitfulness, greed, or lack of learning. Repetition across many regions increases the risk that the skill will propagate bias at scale, especially if excerpts are delivered daily without warning.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
This section explicitly denigrates a foreign population's customs and morality, including statements about violence, lack of etiquette, and 'disordered' marriage practices. In an educational skill that includes vernacular translation and voice output, such content can be amplified and made more accessible, increasing the likelihood of harm or offense.

Static analysis

No suspicious patterns detected.