Back to skill

Security audit

zayn-read

Security checks across malware telemetry and agentic risk

Overview

This skill is a Chinese-language reading workflow that turns user-provided material into structured takeaways and actions, without requesting risky system access.

Install this if you are comfortable using a Chinese-language productivity workflow for reading analysis. Review or translate the templates first if you need English instructions, but the artifact does not show risky permissions or undisclosed automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The skill description and metadata are written entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule, a fixed language/locale without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains user-facing natural language only in Chinese across the listed changelog entries. Under the policy, forcing a specific language without user opt-in or a documented justification can be a locale/language policy violation.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The natural-language instructions and template fields are written entirely in Chinese, including the usage section and invocation template, with no indication that other languages are supported or that Chinese is required for a region-specific reason. This creates a language/locale policy concern because it implicitly constrains users to a specific language without opt-in.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The file's substantive instructions and section headings are written in Chinese, which can constitute a language/locale constraint in natural-language skill materials. There is no indication that users may choose another language or that the Chinese-only presentation is required for a justified region-specific purpose.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.