Back to skill

Security audit

zayn-focus

Security checks across malware telemetry and agentic risk

Overview

This is a narrow productivity skill for simplifying tasks, with no code execution, persistence, credential use, or hidden data access.

Before installing, confirm you are comfortable with a Chinese-language productivity skill and its draft status. It appears safe in security terms because it only guides task analysis and does not request access to files, accounts, tools, credentials, network services, or persistent background behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill’s natural-language instructions and metadata are written entirely in Chinese, including the user-facing description and operational requirements, with no indication that users may choose another language. Under the policy, a skill that effectively enforces a specific language without opt-in or documented regional justification is a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The natural-language content in the changelog is entirely in Chinese, with no indication that language choice is optional or tied to a documented region-specific requirement. Under the policy rule for language or locale constraints, this can be treated as forcing a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The document's instructions and invocation template are entirely in Chinese, including required field labels and the command example. This imposes a specific language on users without any opt-in, alternative locale, or justification that the skill is region-specific.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file contains operational testing instructions entirely in Chinese, which can impose a specific language on users without opt-in. The policy requires flagging language or locale constraints unless the skill offers a choice or clearly documents a justified region-specific limitation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.