Back to skill

Security audit

zayn-ali-rfq-bid

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Alibaba RFQ quotation helper with clear human-confirmation limits and no hidden execution behavior.

Install this if you want a Chinese-language assistant for preparing Alibaba RFQ quote text. Users should still verify prices, inventory, trade terms, warranty, and buyer messages before manually submitting anything on Alibaba.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains user-facing natural language entirely in Chinese across the listed changelog entries. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or language choice is provided.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The heading and all operational instructions are written in Chinese, and the file does not indicate that another language may be used or that Chinese is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This markdown test file uses Chinese throughout and does not indicate that the skill is region-specific or that users may choose another language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.