Back to skill

Security audit

zayn-shipment

Security checks across malware telemetry and agentic risk

Overview

This skill is a Chinese-language checklist and drafting aid for shipment notifications, with no evidence of hidden execution, persistence, or data exfiltration.

Before installing, confirm that a Chinese-language shipment drafting workflow fits your team. Treat order numbers, tracking numbers, shipment documents, and recipient details as sensitive business data, and use the skill to draft or check notices rather than automatically sending messages or changing source records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The README presents the skill entirely in Chinese and does not indicate that language selection is optional or user-controlled. This can override or constrain user preference, reducing transparency and potentially causing miscommunication in shipment notifications, but it does not by itself create a direct security compromise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.