Back to skill

Security audit

道家战略顾问

Security checks across malware telemetry and agentic risk

Overview

This is mainly a Daoist strategy-advice skill, but it needs Review because it can activate on broad life/business advice, declares broad local tool authority, and includes under-scoped covert influence tactics.

Install only if you specifically want a Daoist-philosophy strategy lens. Consider restricting tool access because local write/edit/shell permissions are not needed for ordinary advice. Do not rely on this skill for legal, financial, medical, or crisis decisions, and avoid using its reciprocity or concession frameworks to create hidden obligations or manipulate counterparties.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to activate on common requests about strategy, management, or life decisions, even when the user did not explicitly ask for Daoist framing. That can cause unintended steering into a specialized philosophical modality and bypass user intent, especially in ambiguous contexts.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
These rules make Daoist doctrine the mandatory governing framework for outputs, which can force a cultural or philosophical lens onto users without meaningful consent. In practice, this can bias advice, suppress neutral alternatives, and produce misaligned guidance for users seeking general rather than worldview-specific help.

Ssd 4

Medium
Confidence
92% confidence
Finding
This section operationalizes a delayed-reciprocity influence tactic: give value without disclosure, wait, then seek advantage later while avoiding explicit acknowledgment of the exchange. Even though it is framed as strategy rather than manipulation, it teaches covert social engineering patterns that can be used to cultivate obligation and exploit trust in business or personal contexts.

Ssd 4

Medium
Confidence
88% confidence
Finding
Advising users to redirect others through repeated small concessions is a classic incremental compliance tactic. In this skill's strategic-advice context, that can normalize covert influence and make it easier for users to steer counterparties toward outcomes they might not freely choose if approached directly.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.