Back to skill

Security audit

zayn-delay

Security checks across malware telemetry and agentic risk

Overview

This skill is a documented workflow for handling delivery-delay communications and does not request hidden access, code execution, persistence, or privileged actions.

Installers should be aware that the documentation is primarily Chinese and intended for order/delivery-delay communication workflows. Users should provide only the order, customer, and internal responsibility details needed for the task and verify any customer-facing commitments before sending them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file presents the skill description entirely in Chinese and names the skill with a Chinese display context, but does not state that language choice is optional or that the skill is intentionally limited to Chinese-speaking users for a justified regional purpose. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The markdown content presents all operational test instructions in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context. This can violate a language/locale policy when a skill forces a specific language without user opt-in.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.