Back to skill

Security audit

zayn-decline

Security checks across malware telemetry and agentic risk

Overview

This is a text-only customer communication skill for drafting clear refusal boundaries, with no executable code or hidden high-impact access.

Before installing, confirm that a Chinese-language customer-communication workflow fits your team. Review generated messages for business accuracy, because the skill is designed to draft boundary-setting language from user-provided facts and should not decide final pricing, liability, or policy exceptions on its own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
Lines L5-L9 present the skill's natural-language content exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation, and this file does not indicate any alternative language option or justification.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file's instructional content and template fields are entirely written in Chinese, including the required '渠道和语言' field, with no indication that another language may be used or that Chinese is required for a documented regional or compliance reason. This can constitute a language/locale policy violation because it implicitly constrains skill usage to a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file's operative testing instructions and section content are presented in Chinese, while the surrounding repository context does not indicate that the skill is intentionally region- or language-specific. This can violate a language/locale policy when users are not given an opt-in or alternative language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.