Back to skill

Security audit

人生之路

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Confucian life-planning advice skill with local reference files and an optional HTML report, with no evidence of malware, credential access, network exfiltration, or destructive behavior.

Install only if you want this specialized Confucian life-stage framework to answer broad life-planning questions. For privacy and clarity, ask it to generate an HTML report only when you actually want a saved personal reflection/report file.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains several broad, everyday phrases such as '人生意义', '人生迷茫', and '人生规划' that could match ordinary conversation and activate the skill unintentionally. In an agent environment, overly broad activation can cause the wrong skill to take over user interactions, leading to confusing behavior, privacy over-collection, or unexpected generation of reports when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains very broad, everyday phrases such as life planning, life meaning, and confusion about life, which can cause the skill to activate for generic advice-seeking requests far beyond the narrowest intended scope. Overbroad activation increases the chance of unintended routing, user surprise, and the model taking control of conversations that should remain with the base assistant or require clearer user consent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default branch for '综合请求(默认)' automatically chains interpretation, assessment, advice, and report generation, which makes activation scope unclear and overly expansive. This can lead to the skill performing multiple actions, including file-generating behavior, without sufficiently specific user intent for each step.

Vague Triggers

Low
Confidence
80% confidence
Finding
Using a very generic example like '帮我看看人生' as the basis for clarification guidance encourages the skill to engage on vague, common language that many unrelated conversations may contain. While not directly harmful, it lowers activation precision and increases the risk of accidental invocation and user confusion.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The skill describes generating an interactive HTML report and writing it to an output file, but does not clearly warn users up front that a file will be created. This creates a transparency and consent issue because users may not expect persistent or downloadable artifact generation from what appears to be a conversational advice interaction.

Static analysis

No suspicious patterns detected.