Back to skill

Security audit

zayn-annual-report

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed annual-report writing and review skill with no executable code, hidden persistence, or unrelated data access.

Before installing, consider that this skill is written for Chinese-language annual review workflows and may process sensitive business records that you provide. Use it with appropriate internal reporting data, and verify any referenced shared reporting definitions are files you intended the agent to consult.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The README presents the skill name, usage, inputs, and outputs entirely in Chinese, which can amount to forcing a specific language for users without indicating any language-selection option. The policy for this audit flags language or locale constraints unless the file explicitly offers user choice or clearly justifies the restriction.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill content, including its description and operating instructions, is entirely specified in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no surrounding text indicating that the skill is intentionally region-specific or that users can opt into this language. Per the policy, forcing a specific language without user choice can be a locale-policy violation.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The table headers and all scenario descriptions are written entirely in Chinese, which indicates a language-specific constraint in the skill material. Under the policy, language or locale restrictions should either offer user choice or be clearly documented as justified; this file provides neither.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.