Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md import RAGEvaluator from './src/rag-eval.js';
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local evaluation helper with no evidence of credential access, network exfiltration, persistence, or hidden privileged behavior.
Before installing, be aware that the package metadata appears malformed and the README examples may not run without parameter fixes. From a security perspective, the skill appears low risk: it runs local heuristic evaluation code without external services, secrets, persistence, or privileged system changes.
Referenced artifact was not completely inspected
import RAGEvaluator from './src/rag-eval.js';
Referenced artifact was not completely inspected
import ReasoningEvaluator from './src/reasoning-eval.js';
Referenced artifact was not completely inspected
import HallucinationDetector from './src/hallucination-detector.js';
The markdown documentation is written entirely in Chinese, including headings, descriptions, and API usage guidance, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, imposing a specific language without opt-in is a natural-language policy violation.
The file’s primary natural-language description and inline documentation are written in Chinese, including the title '幻觉检测器' and behavior description, with no indication that language is configurable or that users may choose another locale. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This JavaScript file contains user-facing natural-language descriptions exclusively in Chinese, including the title, method documentation, and event descriptions. For a general-purpose evaluator, this constitutes a locale/language policy issue because the file enforces a specific language context without offering a user choice or documenting that the skill is intended only for a Chinese-speaking environment.
This code file embeds its primary human-readable documentation in Chinese, including the module description and parameter annotations. That creates a language/locale policy issue because the skill does not offer a language choice or explain that it is intentionally region-specific.
The natural-language description in the manifest is written in Chinese only, and the file does not indicate that the skill is intended exclusively for a Chinese-speaking or region-specific audience. Under the policy rule for language or locale constraints, this can be a locale/language restriction without user opt-in or justification.
This code file contains natural-language comments naming the evaluator and operations exclusively in Chinese, such as '统一评估入口', '统一评估器', '运行完整评估', '批量评估', and '生成评估报告'. Under the stated policy, forcing a specific language without user choice or justification is a locale-policy concern.
This JavaScript file contains multiple natural-language strings exclusively in Chinese, including the file description and test inputs/outputs. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate that the Chinese-only behavior is optional or region-specific.
No suspicious patterns detected.