Back to skill

Security audit

南怀瑾思维视角

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only cultural persona skill with real role-play and wellness-disclaimer caveats, but no hidden code, data access, persistence, or exfiltration behavior.

Install only if you want a stylized simulated Nan Huai-Chin perspective. Treat outputs as cultural commentary or role-play, not as medical, mental health, legal, financial, religious, or academic authority, and ask the assistant to exit the role when you want normal factual help.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to answer as if it were the real deceased person, while a later honesty boundary says it is not actually that person. This identity-deceptive framing can mislead users about source authority, especially in philosophical, health-adjacent, or life-advice contexts, and may cause users to over-trust persona-generated guidance.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The manifest markets the skill as academic and cultural study, but the body includes decision heuristics and self-cultivation guidance for real-life use. This scope drift can bypass user expectations and platform safety controls, leading users to treat a cultural-study skill as advice for personal decisions, wellness, or conduct.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The file states it does not involve superstition or prediction, yet later references fate, feng shui, and caveats about concrete predictions. Contradictory safety positioning increases the risk that prohibited or non-evidence-based guidance is smuggled in under an academic label, making enforcement and user informed consent weaker.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list contains broad common terms such as '国学', '佛学', and '禅修', which may appear in ordinary conversation and unintentionally activate the skill. Unintended activation can cause surprise persona-switching, scope takeover, or injection of unsolicited worldview framing into unrelated requests.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill forces a specific persona and linguistic/register style immediately on activation, without checking user preference. While not directly dangerous on its own, this can reduce clarity, impair informed consent, and make it harder for users to distinguish stylistic roleplay from factual assistance.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This section gives concrete wellness guidance on sleep timing, breathing practices, and self-regulation in a way that can be interpreted as actionable health advice, but it does not clearly warn users that the content is cultural/philosophical interpretation rather than medical guidance. Users may rely on statements such as fixed sleep rules, breathing recommendations, or mind-body claims instead of evidence-based care, which is especially risky for people with medical, psychiatric, or sleep disorders.

Static analysis

No suspicious patterns detected.