Back to skill

Security audit

zayn-price

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language pricing strategy guide skill with no code execution, persistence, credential access, or hidden data movement.

Installers should expect a Chinese-language advisory skill for quotation strategy. It may involve entering sensitive business pricing and customer context, so users should provide only information they are comfortable sharing with their agent environment, but the artifact itself does not request external transmission or privileged access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
This markdown file contains user-facing natural-language guidance exclusively in Chinese, including the description and all operating instructions. Under the policy rule for language/locale, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The file's instructional content and template are presented entirely in Chinese, which can amount to a language/locale policy violation when no alternative language option or user choice is provided. The policy specifically flags skills that force a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file’s natural-language instructions and headings are entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate a language/locale policy when a skill implicitly forces one language without user opt-in.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.