Back to skill

Security audit

人生模拟器 | Life Sim

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only Chinese counterfactual life-story skill with no code, external access, persistence, or hidden execution behavior.

Install only if you want a Chinese-language counterfactual life-story prompt that may infer personality and background from short inputs. Be cautious with very personal prompts, and correct the assistant if its assumptions about your culture, age, location, or past choices are wrong.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very common phrases such as '假如' and '如果当初', which can appear in ordinary conversation unrelated to this skill. That makes accidental activation likely, causing the agent to switch into speculative life-simulation behavior without clear user intent and potentially generating unwanted inferences about the user's personality or past choices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction to 'directly start' from a single short phrase and 'not ask follow-up questions' removes an important safety boundary for confirming user intent. In practice, this increases the chance of misfires and pushes the model to immediately generate sensitive, personalized speculation from minimal context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill assumes users are 'mainly Chinese' and hard-codes cultural and locale-specific background into its reasoning. This can cause inaccurate personalization, stereotyping, and inappropriate inferences when the user is not Chinese or does not want that framing, especially since the skill is designed to infer personality and life trajectory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.