Back to skill

Security audit

zayn-availability

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only inventory availability checklist that uses user-provided supply details and does not run code or access systems.

Use this skill if Chinese-language workflow guidance is acceptable and you are comfortable providing the product, supplier, inventory, timing, and optional serial/photo details needed for availability analysis. Avoid entering unnecessary sensitive supplier or customer information.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill metadata and visible instructions are presented entirely in Chinese, including the description and display naming, with no indication that users may choose another language or that Chinese is required for a region-specific compliance reason. This can violate language/locale policy when a skill effectively constrains interaction language without explicit opt-in or justification.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains user-facing natural language only in Chinese, but it does not state that the skill is intended for Chinese-speaking users or offer any language/locale choice. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file presents usage instructions only in Chinese ('使用说明') and does not indicate that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a specific language without opt-in can be a natural-language policy issue.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This markdown file presents all substantive instructions and status sections in Chinese, and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language policy concern under the language/locale rule because it effectively forces a specific language without user opt-in.

Static analysis

No suspicious patterns detected.