Back to skill

Security audit

人性博弈顾问

Security checks across malware telemetry and agentic risk

Overview

This text-only advice skill is coherent, but it can turn ordinary relationship questions into adversarial pressure-and-leverage guidance.

Install only if you deliberately want a hard-nosed interpersonal strategy lens. Use caution for intimate, workplace, family, or low-stakes situations: ask the assistant to prioritize consent, de-escalation, lawful channels, and cultural fit, and avoid using the skill to pressure, shame, threaten, or manipulate real people.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are broad enough to auto-activate on ordinary interpersonal discussions, causing the skill to apply high-suspicion motive analysis and adversarial framing in situations where the user may only want casual advice. In context, this increases the chance of overinterpretation, manipulative guidance, and unsafe relational escalation being injected into benign conversations.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The metadata and description strongly anchor the skill in a Chinese-language and China-context lens without documenting locale limits or offering user choice. This can cause culturally mismatched advice, especially when the skill makes behavioral inferences or strategy recommendations that depend on norms around hierarchy, face, and indirect communication.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The instruction to prioritize Chinese cultural context as a standing rule removes user agency over cultural framing and may bias interpretation of motives and tactics. In a skill that analyzes intent and recommends interpersonal strategy, this can produce inaccurate or socially inappropriate guidance when the user's environment does not share those norms.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are very generic everyday expressions such as '我该怎么回', '这段关系', and '怎么看这个人', which can easily match ordinary conversation outside the user's intent to invoke this skill. This can cause unintended activation, leading the assistant to shift into manipulative or high-stakes interpersonal analysis in contexts where the user did not request it, increasing the chance of inappropriate guidance or privacy-sensitive inference.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The framework explicitly presents '中国社会特有人际面具' and associated interpretations as default analytical lenses without clear user opt-in or localization boundaries. In a skill positioned as broad 'human nature insight' across many life scenarios, this can bias outputs, overgeneralize culturally specific norms, and produce misleading or exclusionary advice for users from other backgrounds.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The text explicitly frames social interaction through a China-specific norm set ('在中国社交中') and presents those norms as default analytical guidance without offering users a choice of cultural lens or warning about limited applicability. In a skill that claims broad applicability across workplace, intimate, business, and family scenarios, this can systematically bias advice, misinterpret users from other cultural contexts, and produce exclusionary or misleading outputs.

Ssd 4

Medium
Confidence
95% confidence
Finding
This section formalizes interpersonal conflict as staged game escalation and explicitly instructs stronger pressure once a situation reaches '僵持期' or '升级期'. That framing can normalize coercive tactics, reduce empathy and de-escalation, and steer users toward harassment, intimidation, or abuse of process against real people.

Ssd 4

Medium
Confidence
97% confidence
Finding
The strategy section explicitly tells the model to map blocked channels, identify what the target fears, and exploit third-party leverage to make 'your problem' become 'their problem.' In this context, that is actionable manipulation guidance that can facilitate coercion, workplace pressure campaigns, relational abuse, or retaliatory escalation under the guise of advice.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.