Back to skill

Security audit

emotion-regulation-sprints

Security checks across malware telemetry and agentic risk

Overview

The skill is text-only and not malicious, but it needs Review because it offers acute mental-health coping guidance without clear crisis boundaries and uses broad triggers.

Treat this as a self-help exercise guide only, not medical care or crisis support. Before installing, consider whether you are comfortable with broad Chinese emotional phrases automatically routing to the skill; users in danger, at risk of self-harm, or in severe distress should be directed to local emergency services, crisis hotlines, or qualified human support instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, everyday expressions such as '焦虑', '很难受', and '心情很差', which can easily appear in ordinary conversation and cause unintended activation. In a mental-health-oriented skill, accidental invocation is more concerning because users may receive sensitive guidance when they did not explicitly seek it, potentially disrupting conversations or surfacing support content at inappropriate moments.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README presents the skill as suitable for acute distress states like '情绪失控', '想哭', and severe anxiety, but it does not state that the skill is not a crisis service, not a substitute for professional care, or what to do in emergencies. In this context, omission of safety boundaries is particularly dangerous because distressed users may rely on the skill during crisis-like situations and delay seeking urgent human support.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list uses broad emotional phrases such as '很难受', '焦虑', and '心烦', which can easily appear in ordinary conversation and cause unintended activation. In a mental-health skill, accidental routing is risky because users may receive self-help guidance when they did not explicitly seek it, and the guidance may be inappropriate for the actual context or severity of their condition.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill provides mental-health coping guidance but does not clearly state that it is not suitable for emergencies, self-harm risk, panic crises, or severe psychiatric symptoms. This is dangerous because distressed users may rely on the skill instead of seeking urgent professional or emergency support, creating a meaningful risk of delayed intervention in high-severity situations.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
86% confidence
Finding
The trigger '焦虑' is extremely short and generic, making it likely to match many unrelated or low-context utterances. In this skill's context, that can cause accidental activation around sensitive mental-health topics, which may lead to mismatched or untimely self-help advice.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
84% confidence
Finding
The trigger '想哭' is a brief, common phrase that may appear in many conversational contexts without indicating intent to invoke this skill. Because the subject matter is emotional distress, unintended activation can be intrusive or may substitute generic self-help guidance where a different response is warranted.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
84% confidence
Finding
The trigger '心烦' is broad and conversational, so it can match ordinary complaints or casual discussion rather than a clear request for emotional-regulation exercises. In a psychology-related skill, this increases the chance of accidental activation and delivery of sensitive advice without explicit user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.