Back to skill

Security audit

人生说明书

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent paid report workflow that sends user-provided life details to a configured Life Book API, with privacy caveats users should review.

Before installing, confirm you trust the configured Life Book service and understand where your birth data, life history, questions, payment status, and generated report will be sent and stored. Avoid submitting sensitive details unless the publisher provides acceptable privacy, retention, deletion, and operator-access terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly collects highly sensitive personal data, including birth details, life history, core personal problems, tradeoffs, and milestones, but the README does not present a clear privacy notice, retention policy, sharing scope, or consent language beyond generation authorization. In this context, the combination of intimate profile data plus a paid remote API workflow increases privacy and misuse risk because users may disclose enough information for profiling, re-identification, or downstream secondary use without being adequately warned.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to default to Chinese unless the user explicitly asks otherwise, which can override user preference and reduce informed consent or usability for users expecting another language. In a payment- and report-generation workflow, forcing a language can increase the risk of misunderstandings around pricing, payment state, or consent details.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.