Back to skill

Security audit

zayn-ali-rfq-scan

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language Alibaba RFQ screening guide that gives bounded business triage advice and does not install code, automate actions, or access accounts.

Install only if a Chinese-language Alibaba RFQ triage workflow matches your needs. Treat its output as business decision support, not an automatic quoting or account action tool; users should still verify RFQ facts, company capability, compliance limits, and quota use before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file presents the skill name, description, and all operating instructions in Chinese, with no indication that users may choose another language or that Chinese is required for a region-specific compliance reason. Under the policy, a forced language or locale without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains user-facing natural language entirely in Chinese, but it does not state that the skill is intended only for Chinese-speaking users or offer any language choice. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file’s instructions and examples are presented entirely in Chinese, which can impose a fixed language/locale on users. Under the policy, language constraints should be opt-in or clearly justified as region-specific, and this file does not provide such a choice or justification.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file's headings and test content are presented in Chinese throughout, and there is no indication that users may select another language or that the skill is intentionally limited to a Chinese-only region or compliance context. This can violate language/locale policy when a specific language is effectively forced without opt-in.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.