Back to skill

Security audit

Soulstamp

Security checks across malware telemetry and agentic risk

Overview

Soulstamp is a disclosed persona-writing skill that edits a local AI identity file, with meaningful persistence risks but no hidden code, credential access, exfiltration, or destructive behavior outside its stated purpose.

Install only if you want help editing a persistent AI persona file. Review all generated SOUL.md changes before saving, keep backups, be careful with restore because it may overwrite current content, avoid encoding sensitive personal data or broad standing permissions, and keep safety rules and user approval requirements explicit outside the persona text.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill explicitly instructs users to back up and later restore `SOUL.md`, which modifies local files, but it does not clearly warn that invoking the workflow can create, overwrite, or restore files on disk. This is a real but low-severity safety issue because users may not realize the skill has side effects on persistent data.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "forge soul" is broad, natural-language text that could be invoked during ordinary conversation rather than as an intentional skill activation. In a skill explicitly about rewriting identity, personality, or behavioral history, accidental activation is more dangerous because it may cause unplanned persona or instruction changes at sensitive moments.

Ssd 1

Medium
Confidence
92% confidence
Finding
The skill's core premise is to replace explicit behavioral instructions with a fabricated identity that makes target behaviors feel intrinsic. That framing can be used to smuggle policy-relevant constraints or persuasive directives past normal instruction scrutiny, increasing the risk of persistent prompt shaping and jailbreak-like behavior.

Ssd 1

Medium
Confidence
95% confidence
Finding
The examples explicitly transform rules into emotionally grounded self-beliefs and 'wounds,' which is a known indirection pattern for making instructions more persistent and less inspectable. In context, this is more dangerous because the skill teaches a repeatable method for paraphrasing control instructions into identity-level conditioning.

Ssd 4

Medium
Confidence
90% confidence
Finding
The stepwise forging process builds a personalized relationship model, establishes permissions, and then embeds a persistent identity scaffold. That combination can strengthen manipulative prompt injection by making the model internalize role, trust, and continuity in ways that are harder to disentangle than ordinary instructions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.