Back to skill

Security audit

zayn-delivery

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese-language delivery-planning skill that structures user-provided order, QC, packaging, logistics, and deadline information without hidden execution or data access.

Install only if a Chinese-language delivery-planning workflow fits your use case. Treat outputs as planning support and continue to verify business facts, payment status, delivery dates, and responsible owners manually before making commitments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The entire skill description is presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This creates a natural-language policy concern because the file effectively imposes a language choice without opt-in or justification.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file contains user-facing natural language entirely in Chinese, which can impose a language requirement on users or maintainers without explicit opt-in. The policy allows locale constraints when they are clearly documented and justified, but no such justification or language choice appears here.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The operative instructions and invocation template are written entirely in Chinese, including the required call phrasing, with no indication that users may choose another language. This can violate language/locale policy when a skill imposes a specific language without explicit opt-in or a documented region-specific justification.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file's instructional content and labels are entirely in Chinese, which can impose a specific language on users or downstream operators. Under the policy, language-specific behavior should either provide user opt-in/choice or clearly document why the locale restriction is required.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.