Back to skill

Security audit

zayn-availability

Security checks across malware telemetry and agentic risk

Overview

This is a narrow inventory-availability wording skill with no executable behavior or sensitive access.

Install this if you want a Chinese-language workflow for carefully describing inventory availability. Review whether the Chinese-only documentation and output labels fit your team; there is no evidence of code execution, data access, or automatic business actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The file presents the skill description and title in Chinese and frames the skill's output behavior around Chinese inventory phrasing, but it does not state that language choice is optional or that the skill is intentionally limited to a Chinese-speaking workflow. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The file’s natural-language content switches to Chinese for the substantive changelog entries, which can amount to forcing a specific language on users if this skill documentation is expected to be generally consumable. There is no indication that the locale is optional, user-selected, or justified as region-specific.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file presents its usage instructions entirely in Chinese (e.g. the section heading and explanatory text) and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The markdown content presents all testing principles and placeholders only in Chinese, which imposes a specific language on users without any visible opt-in or explanation. Under the policy, forcing a language or locale without user choice is a natural-language policy violation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.