Back to skill

Security audit

zayn-search-strategy

Security checks across malware telemetry and agentic risk

Overview

This skill only prepares manual customer-search keyword strategies and does not run searches, scrape sites, access credentials, or modify data.

Before installing, confirm that Chinese-language documentation and prompts fit your workflow. The skill is suitable for planning manual searches, but users should still verify translated search terms, respect platform terms, and avoid turning its keyword lists into bulk scraping or automated outreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The README content is written entirely in Chinese and provides no indication that users may choose another language or locale. Under the policy rule, a skill that imposes a specific language without opt-in or clear regional justification is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The short_description and default_prompt are written only in Chinese, which imposes a specific language on users and downstream agent behavior. There is no indication that this skill is region-specific or that users can opt into another language, so this appears to violate the language/locale policy constraint.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
Line L5 states that the skill establishes a 'local language' search strategy, which suggests a locale or language behavior may be imposed by default. Because the text does not mention user selection, opt-in, or a justified region-specific constraint, it may violate the policy against forcing a specific language or locale.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file presents all user-facing guidance exclusively in Chinese, which can amount to forcing a specific language without user opt-in. The content does not indicate that the skill is intended only for Chinese-speaking users or provide any alternative language option.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The checklist is entirely presented in Chinese, which can impose a specific language on users without any stated opt-in or explanation. The policy requires either a user language choice or a clearly documented reason for the locale restriction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.