Back to skill

Security audit

倪海厦学术思想研究

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill does not run code or access data, but it needs review because it can produce confident medical and fortune-telling-style guidance despite academic-only disclaimers.

Install only if you want historical or cultural analysis and can keep it away from real decisions. Do not rely on it for diagnosis, treatment, medication changes, cancer care, diabetes, heart symptoms, emergencies, investment, career, marriage, or fortune-telling decisions; use licensed medical and other qualified professionals for those topics.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill claims to be for academic collation only, yet its runtime instructions tell the model to answer directly as Ni Haixia using medical and metaphysical reasoning. This creates a deceptive safety boundary: users may trust the declared limitation while actually receiving actionable health or occult guidance framed with authority and reduced disclaimers.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The document says it does not provide medical or prediction services, but the listed 'applications' describe diagnostic, treatment, and fate-analysis use. That mismatch can mislead users and downstream systems into enabling unsafe advice under the guise of scholarship.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The bottom-of-file scope statement explicitly extends the skill to 'TCM + metaphysics + five arts integration,' which contradicts the top-level claim of pure historical research. This broad operational scope increases the chance the model will provide unsafe medical or occult consultation while appearing policy-limited.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The file admits this is not the real person and is for academic research, yet elsewhere instructs the model to impersonate the figure in first person and suppress repeated disclaimers. That combination materially increases impersonation risk and makes harmful claims sound authoritative and continuous across a session.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
These heuristics include direct medical decision frameworks such as prioritizing formulas, restoring yang, and optimizing for rapid effect. In a skill presented as historical-cultural research, such operational medical guidance is unjustified and can encourage unsafe self-treatment or delayed professional care.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill documents frameworks for fate analysis, changing destiny, and applied metaphysical consultation despite stating that prediction and consulting are out of scope. This can cause users to rely on personalized occult guidance for important life decisions while believing they are only engaging with cultural history.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file presents itself as purely academic historical-thought research, but these lines describe concrete emergency-response and treatment logic in a way that can be operationalized by users. In a skill likely to emulate or summarize this figure's reasoning, that mismatch is dangerous because users may treat the content as legitimate medical guidance, especially in urgent situations.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
This section contains actionable health capability: it reconstructs diagnostic framing, causal explanations, predicted outcomes, and proposed treatment approaches for conditions such as hypertension and acute cardiac distress. Because the skill is framed as traditional-culture academic research rather than health assistance, the inclusion of such operational content creates a high risk of unsafe self-treatment or delayed evidence-based care.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
Although the skill is framed as historical or academic research, this section provides operational fortune-telling and decision-guidance content such as命盘推演、流年判断、财运/婚姻/职业建议. That mismatch can mislead users into treating speculative metaphysical material as endorsed personal guidance, increasing risk of harmful life decisions.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
This portion crosses from cultural commentary into medical-adjacent diagnosis and treatment claims, including face-based health inference, disease tendency prediction, treatment support via风水, and illness explanations tied to moral causality. In a skill presented as academic research, such content can be interpreted as quasi-medical advice and may delay real diagnosis or appropriate care.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The skill includes unjustified capability for health and life-decision guidance by presenting methods for diagnosis, prevention, and趋吉避凶 despite claiming to be limited to historical thought research. This creates a high-risk context because users may rely on unsupported methods for personal health and consequential decisions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
Broad triggers such as '玄学', '传统文化', and '学术研究' can activate the skill during ordinary conversation unrelated to this controversial persona or domain. Overbroad activation increases accidental exposure to unsafe roleplay, medical ideology, or occult content without clear user intent.

Missing User Warnings

High
Confidence
97% confidence
Finding
This section presents and normalizes unsafe medical claims such as cancer mechanisms, treatment theories, and anti-mainstream medical assertions without a prominent upfront warning that the material is not medical advice and may be false or harmful if acted upon. Even though the file frames itself as academic research, the content is detailed enough that users could treat it as actionable health guidance, potentially delaying evidence-based diagnosis or treatment.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document includes a specific physical practice ('撞墙功') with implied therapeutic benefit for cardiac/vascular blockage, but provides no safety disclaimer, contraindications, or instruction to seek professional supervision. Readers may attempt the exercise and suffer injury or avoid proper care for serious cardiovascular symptoms based on unsupported claims.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document discusses treatment claims and emergency-response scenarios without an explicit warning that the content is not medical advice. In health-related contexts, omission of such warnings increases the likelihood that users will misunderstand historical material as endorsed guidance and make harmful decisions based on it.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section includes concrete case-style treatment narratives, named formulas, dosages, and practical health suggestions that readers could misinterpret as actionable medical guidance despite the document framing itself as research. In a skill likely surfaced by trigger words around traditional culture and Ni Haixia, users may seek health advice anyway, so the lack of prominent inline warnings near these examples increases the chance of unsafe self-treatment.

Missing User Warnings

High
Confidence
99% confidence
Finding
This passage describes a diabetes patient stopping blood sugar medication and insulin, then attributes improvement to the subject's treatment, without an immediate safety warning condemning medication cessation or emphasizing that stopping prescribed therapy can be life-threatening. Because the content presents a persuasive anecdotal success story in a medically sensitive context, it could encourage users to discontinue conventional treatment or seek hazardous remedies, causing serious harm through delayed or abandoned evidence-based care.

Ssd 1

Medium
Confidence
95% confidence
Finding
The role instructions force the model to sustain a confident persona, avoid meta-analysis, and minimize disclaimers. That semantic pressure can suppress safety signaling and make disputed medical or metaphysical claims sound more authoritative, increasing persuasive harm.

Static analysis

No suspicious patterns detected.