Back to skill

Security audit

SBTI(Sociability, Boldness, Thinking, Independence)人格测试,聚焦**社交性**、**果敢度**、**思维模式**、**独立性**四大核心维度,精准刻画人格特质。 本技能将专业测评体系 AI 化,无需复杂操作,即可快速完成测试并生成结构化报告,帮你深度认识自我、优化人际互动、明确职业方向,解决自我探索、职场适配、人际沟通等高频需求。

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only personality questionnaire that collects expected self-assessment answers and generates a report, with no code execution, credential access, network use, or hidden persistence found.

Install only if you are comfortable answering personality, relationship, self-worth, and alcohol-related questions in chat. Treat the report as entertainment or self-reflection rather than medical, psychological, hiring, or career-decision advice, and consider how your agent platform stores chat history before sharing sensitive personal details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly describes collecting and analyzing users' personality-test answers, which can reveal sensitive psychological traits, but it provides no privacy, retention, consent, sharing, or storage guidance. Even though this is documentation rather than executable code, the absence of data-handling safeguards can lead to unsafe deployment and user disclosure of sensitive personal information without informed consent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases include very generic terms like “人格测试” and “人格分析”, which can match broad, everyday user requests and cause this skill to activate unintentionally. In context, that can route users into a long questionnaire they did not explicitly request, increasing misfires and incorrect skill selection rather than creating a direct code-execution risk.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill is authored entirely in Chinese and instructs Chinese-only interaction without offering a language fallback or making the locale restriction explicit. This is primarily a usability and access-control issue: users in other languages may misunderstand prompts, consent poorly to the questionnaire flow, or receive unusable output.

VirusTotal

39/39 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.