Back to skill

Security audit

The Primer

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent personal coaching setup, but it can persistently change how the agent behaves and schedule recurring activity without enough separate user control.

Install only if you intentionally want a persistent personal coaching profile that may change future agent behavior. Before setup, review the exact AGENTS.md and SOUL.md edits, decline or manually manage cron reminders unless you really want recurring automation, and decide what personal reflections should be stored, retained, or deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill manifest presents a tutoring/personality feature, but the body contains concrete file read/write operations without declaring or scoping those capabilities. This creates a trust and review gap: users and systems may invoke the skill expecting conversational behavior while it silently modifies workspace state.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill claims to provide personal-growth tutoring, yet it instructs the agent to create files, delete state, update configuration artifacts, and perform system-level setup steps. That mismatch is dangerous because it hides operational side effects behind a benign social-purpose wrapper, increasing the chance of unauthorized or surprising changes.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The cron-job automation is a persistent execution mechanism that is not disclosed by the manifest's tutoring-focused description. Hidden persistence significantly raises risk because it can continue acting after the immediate interaction and may surprise the user with recurring behavior or data processing.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Editing core agent identity/config files such as AGENTS.md and SOUL.md changes how the broader agent behaves beyond this single skill invocation. For a personal-growth tutor, this is unjustified privilege expansion and could permanently alter startup behavior, prompt hierarchy, or future decision-making in ways the user did not anticipate.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Creating cron jobs establishes persistent autonomous execution, which is far beyond what is necessary for a tutoring skill. This grants the skill durable influence over the environment and can enable repeated prompts, file access, or logging without fresh user intent.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The script does more than generate a user-facing PRIMER.md: it persistently modifies AGENTS.md and SOUL.md, which are agent-governance files that can affect future assistant behavior across the workspace. That scope expansion is security-relevant because it changes long-lived instructions outside the user artifact the skill claims to set up, creating an unexpected persistence mechanism.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Injecting persistent instructions into AGENTS.md and SOUL.md gives the skill the ability to reshape how the agent behaves in later sessions, not just during the setup flow. In the context of a personal-development skill explicitly described as 'subversive' and challenging, this persistence can override user expectations and establish durable behavioral control beyond the justified purpose.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs the agent to create, update, and delete workspace files during setup without a clear user-facing warning at the point of action. That omission undermines informed consent and can lead to unwanted persistence of sensitive personal information or accidental loss of setup state.

Missing User Warnings

High
Confidence
99% confidence
Finding
The cron-job instructions introduce persistent automated system changes without a prominent warning or consent flow. Because scheduled tasks can outlive the session and operate repeatedly, failing to disclose them is especially dangerous and can amount to stealthy persistence.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The inserted 'Primer Role' text tells the agent 'You're not just a butler — you're a tutor with opinions about who they should become' and 'Your job is to notice when they're drifting,' which imposes a strong behavioral mode as persistent instruction. Because this is written directly into SOUL.md rather than being a runtime suggestion or an explicitly accepted profile, it creates coercive role configuration without clear per-change opt-in.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill asks the agent to persist highly personal disclosures such as life stage, purpose, patterns, and accountability contacts across sessions. Persisting this kind of sensitive self-reflective data increases privacy risk, especially when stored in plain workspace files without retention limits or clear access boundaries.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill instructs ongoing logging of daily reflections, check-in responses, and evolving personal context into memory files and PRIMER.md. Continuous accumulation of intimate behavioral data raises surveillance and confidentiality concerns, particularly when combined with persistent automation and cross-session reuse.

Ssd 1

High
Confidence
96% confidence
Finding
The string added to AGENTS.md labels PRIMER.md as 'the subversive tutor protocol,' which semantically elevates the inserted document into a control instruction for future sessions. In a governance file, language that reframes the assistant as a 'subversive tutor' is especially risky because it can normalize deviations from standard assistant behavior and encourage stronger-than-expected intervention.

Ssd 1

High
Confidence
97% confidence
Finding
The SOUL.md insertion explicitly grants the agent an opinionated, corrective role over 'who they should become' and says its job is to detect drift from the user's purpose. Persistently embedding that authority in a core identity/governance file creates a durable shift in agent posture toward supervision and correction, which is disproportionate for a coaching skill and can influence unrelated future interactions.

Ssd 4

Medium
Confidence
88% confidence
Finding
The persona_permissions table escalates from benign observation to stronger interventions like 'Challenge avoidance,' 'Suggest the harder path,' 'Protective friction,' and 'Call out the absurd.' On its own this is a coaching design choice, but combined with persistence into governance files it normalizes increasingly forceful agent behavior and raises the risk of overreach in future sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.