Back to skill

Security audit

Dream Analyzer - AI解梦与潜意识分析

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only Chinese dream interpretation skill with no code or system access, though its blunt psychological style may be emotionally sensitive.

Install only if you want Chinese-language dream interpretation with a direct, non-comforting tone. Do not treat its output as diagnosis, therapy, or professional mental-health advice, especially for crisis, trauma, self-harm, delusions, or severe distress.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill performs quasi-psychological interpretation of dreams, personality, and subconscious conflict while explicitly instructing the model to be blunt ('不要安慰', '只要真相') and providing no warning that outputs are speculative, non-clinical, and potentially emotionally sensitive. This can mislead vulnerable users into treating generated interpretations as authoritative mental-health insight, increasing risk of distress, self-misdiagnosis, or harmful behavioral decisions.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill is written to operate entirely in Chinese and does not offer a language choice or document that it is intentionally restricted to Chinese-speaking users. While not a classic security flaw, this can cause misunderstanding of sensitive psychological-style content if triggered for users in other languages, reducing informed consent and increasing the chance of misinterpretation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.