Back to skill

Security audit

zayn-minutes

Security checks across malware telemetry and agentic risk

Overview

This is a meeting-minutes formatting skill with no code execution, persistence, credential handling, or external data movement.

Install this if you are comfortable using a Chinese-language skill for meeting-minutes drafting. Users should still review generated minutes because the skill depends on the accuracy and completeness of the meeting notes they provide.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The manifest description and visible skill naming are entirely in Chinese, and the document provides no opt-in, language selection, or explanation that this is a China-specific or Chinese-only skill. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The natural-language entries in the changelog are presented exclusively in Chinese, with no indication that language selection is optional or user-configurable. Under the policy provided, forcing a specific language without user opt-in can constitute a language/locale policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file presents the usage instructions entirely in Chinese ('使用说明') and provides no indication that other languages are supported or that Chinese is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file’s operative testing instructions and section content are presented in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.