Back to skill

Security audit

self-relationship

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent self-reflection skill with no executable behavior, but users should treat it as educational support rather than crisis or clinical care.

Install only if you want an agent to apply a reflective, self-acceptance-oriented style when you discuss self-understanding or personal growth. Do not rely on it for diagnosis, treatment, self-harm, imminent danger, or urgent mental health support; use qualified professional or crisis resources for those situations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The README says the skill auto-loads when users mention broad, everyday topics such as self-understanding, self-growth, or related Chinese phrases. Because these triggers are semantically wide and overlap with normal conversation, the skill may activate unexpectedly and steer interactions in sensitive psychological contexts without clear user intent. In a self-reflection skill, that increases the chance of overreach, unwanted behavioral guidance, or accidental substitution for more appropriate support.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README states that the skill will automatically load when users mention very broad self-reflection topics, without clear exclusion criteria or stronger routing boundaries. In an agent ecosystem, such broad triggers can cause over-activation in unrelated or sensitive conversations, leading the skill to influence responses outside its intended scope and potentially override more appropriate specialized handling.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The phrase 'and similar topics' creates an open-ended trigger boundary, which can cause the skill to activate in conversations that only loosely relate to self-reflection. In a safety-sensitive domain touching mental health and personal decision-making, ambiguous activation increases the chance of the skill steering conversations outside its intended scope or overriding more appropriate specialized behaviors.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Describing automatic loading based on topic examples rather than precise trigger rules makes invocation behavior unpredictable. This is risky because the skill addresses self-acceptance and psychological framing; overbroad activation could insert reflective guidance into contexts where users need different support, including crisis handling or non-mental-health tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README describes activation for broad topics like self-acceptance, self-understanding, and personal growth, which are common in ordinary conversation. In an auto-loading skill system, this can cause the skill to activate unintentionally and steer responses with its embedded guidance even when the user did not explicitly request this mode.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The installation/usage text says the skill loads automatically when users mention a wide list of common phrases, without scope constraints or disambiguation. This increases the chance of over-triggering across normal discussion, causing unsolicited behavioral shaping or prompt-context injection from the skill into unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README states the skill will automatically load when users mention broad, topic-based phrases such as self-acceptance or self-growth. Broad automatic triggers can cause unintended invocation in unrelated or only loosely related conversations, which may steer sensitive discussions without clear user intent or explicit consent. In a self-reflection/mental-wellbeing context, this is more concerning because mistaken activation can influence vulnerable users.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger description is intentionally broad, covering many self-help and self-understanding topics in two languages. That increases the chance the skill will activate for ambiguous user messages and steer users into psychologically framed guidance when they did not explicitly request it, which is risky in a mental-health-adjacent domain. The skill’s otherwise careful boundaries reduce severity, but over-invocation can still create inappropriate reliance or misrouting.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The boundary section says to encourage professional support for serious psychological crisis, but it does not provide a concrete escalation warning or immediate action guidance for users expressing self-harm, suicidality, or imminent danger. In a self-relationship skill, users may present exactly those situations, and vague boundary language can delay urgent help-seeking or leave the model responding too conversationally in a crisis.

Static analysis

No suspicious patterns detected.