Back to skill

Security audit

SkillTree

Security checks across malware telemetry and agentic risk

Overview

SkillTree is a coherent personalization skill, but it needs review because it automatically profiles recent chats, stores evolving personal context, and encourages some actions before confirmation.

Install only if you want chat-history-based personalization and persistent agent memory. Before use, require explicit approval for emails, messages, calendar/file changes, public posts, purchases, and share cards, and periodically review or reset stored profile data if it captures sensitive or inaccurate details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (29)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The Companion path explicitly instructs the agent to remember personal details from conversations and there is no stated consent flow, retention limit, or purpose limitation. Persistent memory of personal details increases the risk of unintended disclosure, oversharing across contexts, and collection of sensitive user data beyond what is necessary for the feature.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The Expert path says the agent should proactively track domain updates, which implies ongoing monitoring or external information gathering beyond the core documented interaction model. Without clear scope, consent, or implementation boundaries, this can lead to unexpected background data access, external calls, or behavior users did not request.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to analyze the last 50 messages and infer behavioral and emotional traits without any stated consent, minimization, or user-facing justification. This creates a profiling risk because sensitive preferences and emotional patterns may be derived from ordinary conversation and then used to shape future interactions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Companion mode directs the system to remember personal details and emotional cues, but the skill provides no retention limits, consent flow, or purpose boundaries. That makes it easy for the agent to accumulate sensitive user context over time and reuse it in ways the user did not expect.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill proposes automatic class recommendation based on broad conversational patterns such as asking tech questions, venting, or requesting writing help. Because these triggers overlap heavily with normal user conversation, the skill can activate or steer behavior without a clear, explicit user opt-in, creating prompt-routing ambiguity and increasing the chance of unintended mode changes.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is entirely in Chinese and presents all interaction flows, labels, and examples in Chinese without offering any language selection or fallback. This can coerce or exclude users who do not understand Chinese, creating accessibility and usability issues, though it is not a direct security compromise.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template explicitly says it will analyze past conversations automatically on first experience, but provides no privacy notice, consent prompt specific to conversation analysis, or explanation of what data is used. This creates a real privacy risk because users may not expect retrospective profiling from prior chats, especially when the output includes inferred traits, strengths, weaknesses, and a recommended path.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The share card exposes profile attributes such as class, level, ability scores, percentile ranking, and streak without any warning that sharing may reveal behavioral or inferred personal information. While the user likely initiates sharing, the absence of a caution increases the chance of oversharing sensitive preference or profiling data.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The phrase '安装后自动触发' indicates the skill runs automatically on installation without clearly limiting when it executes or what data it may access. In this skill's context, that broad trigger is paired with profiling behavior, which increases the risk of unexpected processing and user surprise without informed consent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The text says it analyzes '过去的对话' to generate an 'Agent profile' but does not present any privacy warning, consent flow, retention notice, or scope limitation. This creates a real privacy risk because users may not expect historical conversations to be mined for profiling immediately after installation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The Companion path explicitly promises remembering user preferences and inferring emotional state, but it does not disclose limits, consent, retention, or how sensitive personal data is handled. This can mislead users into sharing emotional or personal information without understanding the privacy implications, increasing risk of oversharing, profiling, or inappropriate emotional inference.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The Efficiency path normalizes autonomous action with phrases like 'do first, ask later' and examples such as sending email without confirmation, but it does not define safety boundaries for external side effects. In an agent context, this can cause unintended actions affecting communications, files, calendars, or other systems without adequate user approval.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The efficiency-mode examples explicitly normalize taking external actions such as sending email and completing multiple tasks without explicit confirmation or clear guardrails. In an agent skill context, this can lead to unauthorized actions, accidental changes to user data, or operations against external systems if the agent over-applies the 'can do without asking' principle.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The companion-mode section encourages remembering user preferences, emotional state, and past conversations without explaining consent, retention, scope, or deletion controls. In practice, this can create privacy risks through unexpected storage of sensitive personal data and over-collection of emotional or behavioral signals.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly advertises automatic analysis of chat history but provides no notice, consent flow, scope limitation, or data-handling warning. In an agent skill, prior conversations may contain sensitive personal, business, or credential-like information, so silently processing them creates a real privacy and trust risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill description says it auto-starts after install and immediately analyzes prior chat history, again without a warning or consent checkpoint. Automatic execution on install increases the likelihood that sensitive historical content is processed before the user understands the feature or can decline it.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README states that the skill will automatically analyze past conversation history immediately after installation, but it does not clearly disclose what data is accessed, how much history is processed, whether consent is required, or how results are stored. In an agent skill context, silent retrospective analysis of conversation data creates a meaningful privacy risk because users may expose sensitive personal, professional, or confidential information without informed opt-in.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README encourages sharing a generated ability card to Moltbook, but does not warn that the card is derived from user interactions and may reveal behavioral traits, usage patterns, identity cues, or inferred characteristics. Sharing user-derived profile data to an external platform without clear disclosure or confirmation can lead to unintended privacy leakage and oversharing.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The Efficiency trigger phrases include common conversational feedback such as 'fast,' 'direct,' and 'too verbose,' making accidental activation likely during ordinary chat. Because path changes alter behavior and may affect follow-up actions, broad triggers can cause unconsented state changes and unpredictable agent behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The Companion path uses broad phrases like 'friend,' 'chat,' and 'don't be so robotic,' which are common user expressions and can easily be interpreted as path-switch commands. This creates a risk of silent behavioral reconfiguration, especially because this path also encourages memory of personal details and emotional adaptation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The Expert path trigger phrases such as 'professional,' 'deep,' 'detailed,' and 'why' are generic and highly likely to occur in normal requests. This can unintentionally switch the agent into a mode with different behaviors, including proactive tracking, without a clear user decision.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill's first activation logic directs immediate analysis of the last 50 chat messages before presenting a clear warning or obtaining informed consent. Reviewing prior conversation history can expose sensitive personal, professional, or confidential information and is especially risky because it happens automatically on activation conditions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The first-activation flow says the agent should immediately analyze prior conversation history, but there is no privacy warning or affirmative consent step before doing so. Silent retrospective analysis is risky because users may not realize past chats will be mined to generate profiles and recommendations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The efficiency-mode trigger phrases are broad everyday expressions such as '快', '简洁', and '直接', so the mode could activate from normal conversation rather than deliberate intent. Unintended activation can alter agent behavior and data collection patterns without the user's informed choice.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Companion-mode triggers like '朋友', '聊天', and '懂我' are highly ambiguous and can occur in ordinary conversation. Because this mode also encourages remembering personal details and emotional adaptation, accidental activation increases privacy and manipulation risk more than a simple cosmetic mode change would.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.