Back to skill

Security audit

zayn-rma

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language RMA decision checklist with no executable code, system access, persistence, or hidden behavior.

Install this only if you are comfortable using a Chinese-language RMA workflow. Treat its outputs as decision support: it is designed to flag missing evidence and boundaries, not to authorize refunds, replacements, legal positions, or management decisions by itself.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The file's natural-language content switches to Chinese for the substantive changelog entries, which can impose a language constraint on users or maintainers without any visible opt-in or justification. Under the language/locale policy, this is a natural-language policy concern unless the skill explicitly documents that it is intended for a Chinese-language or region-specific context.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The file’s instructional content and template are presented only in Chinese, and there is no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file's headings and checklist content are entirely in Chinese, which can amount to a language-policy constraint if users are not given an opt-in or alternative language. The file does not state that the skill is region-specific or that Chinese is intentionally required.

Static analysis

No suspicious patterns detected.