Back to skill

Security audit

zayn-complaint

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language workflow for organizing hardware complaint evidence and does not install code, run commands, or take direct account actions.

Installers should expect this skill to process customer complaint and order evidence. Use it with appropriately redacted customer data where possible, and the publisher should clarify whether Chinese is the intended operating language or whether users may interact in other languages.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The manifest description and displayed skill naming/content are entirely in Chinese, and the file does not state that the skill can operate in other languages or that Chinese is a required, justified locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The file contains user-facing natural language entirely in Chinese, but does not state that the skill is China-specific or that Chinese is optional. Per the policy, forcing a specific language without opt-in can be a locale/language policy violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The markdown instructions and invocation template are entirely written in Chinese, including the required prompt text at L10 and all input fields at L12-L34. There is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only regional context, which creates a natural-language locale policy concern.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The file’s instructional content from the section headings through the checklist is presented entirely in Chinese, with no note that the skill is Chinese-only or that users may choose another language. This can violate a language/locale policy when a skill implicitly forces one language without explicit opt-in or documented regional justification.

Static analysis

No suspicious patterns detected.